Russian national facing 20 years for malware campaign that infected 80,000 freelancers
A Russian national has been indicted on charges related to a 2016 malware campaign that infected over 80,000 freelancers. He used a variant of the TVRAT malware to steal data and commit fraud, targeting users of a freelance employment tech company. The investigation is ongoing, and Aktulaev faces a potential 20-year prison sentence.
A Russian national, Searzhudin Tamirlanovich Aktulaev, is facing multiple charges related to a malware campaign he conducted in 2016. He was arrested in Cyprus in May 2025 and subsequently extradited to the U.S. for his involvement in infecting the devices of over 80,000 freelancers. The indictment dates back to 2021, when prosecutors alleged Aktulaev utilized a variant of the TVRAT malware – also known as TVSPY or TeamSpy – through a freelance employment tech company’s online messaging platform.
Between June 2016 and November 2017, Aktulaev leveraged these fake user accounts to spread the malware, primarily through malicious Microsoft Excel attachments. When these documents were opened, users were prompted to take actions that downloaded the malware. The Justice Department has not yet disclosed the name of the targeted freelance company.
Aktulaev exploited a vulnerability in TeamViewer, a remote access tool, and another vulnerability in VNC Viewer to gain unauthorized access to victims’ devices. His goal was to steal data and commit fraud, and he maintained a document containing stolen e-commerce login credentials and personal information from hundreds of victims.
Aktulaev is currently in federal custody and is scheduled for his next hearing on October 5. The investigation is ongoing, and he faces a maximum sentence of 20 years in prison if convicted.
