A Russian national, Searzhudin Tamirlanovich Aktulaev, has been indicted in California for allegedly using hundreds of fake freelance-platform accounts to send malicious Excel files that infected about 80,000 users. The campaign deployed TVRAT and DarkVNC to steal data from victims, including many in the US, and used the stolen information for fraud and other crimes. #SearzhudinTamirlanovichAktulaev #TVRAT #DarkVNC #TeamViewer #VNCViewer
Keypoints
- Aktulaev was indicted for conspiracy, malicious code transmission, and aggravated identity theft.
- The attackers created about 255 fake accounts on a freelance job platform.
- Roughly 80,000 users were targeted with malicious Excel attachments in phishing messages.
- TVRAT and DarkVNC were used to gain remote access and steal data from infected systems.
- Investigators found victim databases and stolen credentials on command-and-control infrastructure.
Read More: https://www.helpnetsecurity.com/2026/09/03/russian-national-indicted-freelance-platform-malware/