Russian National Indicted in Phishing Campaign Targeting 80,000 Freelancers
A federal grand jury in California has indicted a Russian national for allegedly orchestrating a phishing campaign that infected thousands of freelancers with TVRAT and DarkVNC malware.
Forty-year-old Sajudin Tamirlanovich Aktulayev was arrested at Larnaca Airport in Cyprus in May 2025 and later extradited to the United States.
According to court documents filed in June 2021 and unsealed this week, Aktulayev allegedly abused online messaging platforms to conduct phishing attacks against users of an unnamed freelance employment technology company in the Northern District of California.
Between June 2016 and November 2017, the defendants reportedly used 255 fraudulent user accounts to send Microsoft Excel attachments containing malicious macros to approximately 80,000 freelancers. Victims who opened the attachments were directed to download malware onto their computers.
The campaign allegedly deployed TVRAT, also known as TeamSPy and TVSPY, as well as DarkVNC. The malware enabled the attackers to remotely control infected systems through TeamViewer and VNC Viewer, respectively.
“Both the TVRAT and DarkVNC malware sent stolen data from victims’ computers to command and control servers, where the stolen data was collected and used by Aktulayev and his co-conspirators to commit fraud and other criminal activities,” the U.S. Department of Justice stated.
“The command and control domain was paid for using virtual currency, and thousands of computers infected with the TVRAT malware were ‘calling back’ to the command and control domain hosted in the United States.”
Investigators say the attackers also stole victims’ e-commerce login credentials and personally identifiable information. Approximately half of the identified victims were located in the United States, including many in Northern California.
Aktulayev is currently in federal custody and is scheduled to appear before U.S. District Judge Donato on October 5.
On Monday, the U.S. Department of Justice also announced a joint international operation to disrupt the infrastructure of the Russian-linked Sality botnet. The action involves global law enforcement agencies and private-sector cybersecurity partners.
The overall prevention score can hide what happens after the initial access. If an attacker uses valid credentials, your defenses drop dramatically.
The Blue Report 2026 measures defense techniques by technology across 338 million simulations run in customer production environments.
Source: www.bleepingcomputer.com



