Russian national indicted after malware sent to 80,000 freelancers
This is how a job platform became a major malware delivery service.

Getty Images For Unsplash.
- A California grand jury indicted Searzhudin Aktulaev over a malware campaign targeting about 80,000 freelancers.
- Prosecutors say fake accounts sent malicious Excel files that installed remote-control malware when victims enabled macros.
- Investigators found stolen e-commerce logins and personal data for hundreds of victims in an email account.
- Aktulaev faces fraud, malware, unauthorized access, and identity theft charges, with over 35 years possible.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
A California federal grand jury has indicted a Russian man for his part in a malware campaign that infected over 80,000 freelancers.
Forty-year-old Searzhudin Tamirlanovich Aktulaev was extradited to the United States after being arrested in Cyprus in May 2025.
According to the indictment, filed on June 1st, 2021, and unsealed on Tuesday, the defendant conspired to distribute malware to approximately 80,000 freelance users of a well-known freelance employment technology company in the Northern District of California.
Aktulaev wrote several messages, which were sent from 255 fake user accounts. These messages contained malicious Microsoft Excel attachments. Victims who opened the attachments were prompted to run a macro, which in turn downloaded malware.
According to the US Department of Justice, Aktulaev used two types of malware: TeamViewer Remote Access Trojan (TVRAT) and DarkVNC.
TVRAT exploited a vulnerability in TeamViewer, which allowed Aktulaev to remotely control infected computers. DarkVNC did the same with a competing remote administration tool called VNC Viewer.
“Both TVRAT and DarkVNC malware sent stolen data from a victim computer to a command-and-control server, from which the stolen data was collected and used by Aktulaev and his co-conspirators to commit fraud or other criminal activity,” the Department of Justice said in a press release.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
The command-and-control domains were paid for using virtual currency. At least one command-and-control domain was hosted in the US.
Law enforcement officers found a document on an email account that was used in the criminal activities, containing e-commerce login credentials and personally identifiable information for hundreds of victims.
Aktulaev is currently in federal custody and is scheduled to appear in court on October 5th, 2026. He’s being accused of conspiracy to commit wire fraud, transmitting malware to damage protected computers, gaining unauthorized access, and aggravated identity theft.
If convicted, Aktulaev risks going to jail for over 35 years and paying $1 million in fines combined, or twice the gross gain from the offenses, whichever is greater.