Aktulaev fake-account freelancer phishing campaign
Campaign
Summary
Hide ▲
Show ▼
Searzhudin Tamirlanovich Aktulaev was charged by the DoJ over a 2016-2017 phishing campaign that used roughly 255 fake accounts on a freelance platform to send malware-laced Excel attachments to about 80,000 users. The messages delivered TVRAT and DarkVNC, enabling remote control of infected computers and the theft of e-commerce login credentials and PII. The platform was described as a well-known freelance employment technology company based in the Northern District of California, and many infected systems were in the United States. Aktulaev was extradited from Cyprus on August 28 and made his initial appearance in San Francisco on August 31, where he was remanded to federal custody.
Related Happenings
Aktulaev federal indictment and extradition for phishing-malware scheme
Law Enforcement
H score32
First: 02.09.2026 12:06
Last: 02.09.2026 12:06
Sources 1
How related:
The U.S. Department of Justice (DoJ) has charged a Russian national, extradited from Cyprus on August 28, with using roughly 255 fake accounts on a freelance platform to send malware-laced Excel attachments to about 80,000 of its users in 2016 and 2017.
About this happening:
The DoJ charged Searzhudin Tamirlanovich Aktulaev after his extradition from Cyprus and arrest in May 2025, alleging a 2016-2017 phishing-and-malware campaign...
Aktulaev federal indictment and extradition for phishing-malware scheme
Law EnforcementHow related: The U.S. Department of Justice (DoJ) has charged a Russian national, extradited from Cyprus on August 28, with using roughly 255 fake accounts on a freelance platform to send malware-laced Excel attachments to about 80,000 of its users in 2016 and 2017.
About this happening: The DoJ charged Searzhudin Tamirlanovich Aktulaev after his extradition from Cyprus and arrest in May 2025, alleging a 2016-2017 phishing-and-malware campaign...
TVRAT and DarkVNC phishing infection activity
Malware Activity
H score34
First: 02.09.2026 12:06
Last: 02.09.2026 12:06
Sources 1
How related:
DarkVNC, both of which gave the operators remote control of the infected computer.
About this happening:
TVRAT and DarkVNC powered a phishing malware operation that used 255 fake accounts on a freelance platform to send malicious Microsoft Excel attachments with m...
TVRAT and DarkVNC phishing infection activity
Malware ActivityHow related: DarkVNC, both of which gave the operators remote control of the infected computer.
About this happening: TVRAT and DarkVNC powered a phishing malware operation that used 255 fake accounts on a freelance platform to send malicious Microsoft Excel attachments with m...
Jewelbug multi-region government webmail espionage campaign
Campaign
H score56
First: 13.08.2026 21:15
Last: 13.08.2026 21:15
Sources 1
About this happening:
Jewelbug is a China-linked hack-for-hire campaign that paired government and military espionage with cryptocurrency fraud. The operation compromised 15 governmen...
Jewelbug multi-region government webmail espionage campaign
CampaignAbout this happening: Jewelbug is a China-linked hack-for-hire campaign that paired government and military espionage with cryptocurrency fraud. The operation compromised 15 governmen...
Latest development: 14.08.2026 10:54
Broadcom's Symantec and Carbon Black linked Jewelbug's espionage and crypto-fraud operations to XG-Web, a React/Node.js/MySQL control panel used to manage browser-based access, host obfuscated payloads in public Google Docs, and coordinate the com.microsoft.runedge native-messaging host to run operator commands. The analysis also described the malicious PDF Viewer extension for Google Chrome and Mozilla Firefox, and said the campaign targeted government organizations and militaries across the Middle East, Southeast Asia, and South Asia.
Kratos ecosystem shift changes threat-actor operations
Threat Actor Meta
H score39
First: 22.07.2026 02:07
Last: 22.07.2026 02:07
Sources 1
About this happening:
The Kratos phishing-as-a-service ecosystem was dismantled after it scaled to more than 1,800 criminal customers, exposing a subscription model that drove roughly 15,000...
Kratos ecosystem shift changes threat-actor operations
Threat Actor MetaAbout this happening: The Kratos phishing-as-a-service ecosystem was dismantled after it scaled to more than 1,800 criminal customers, exposing a subscription model that drove roughly 15,000...
Germany-U.S. Kratos PhaaS takedown and developer arrest
Law Enforcement
H score39
First: 22.07.2026 02:07
Last: 22.07.2026 02:07
Sources 1
About this happening:
Authorities in Germany and the U.S. seized more than 200 servers and arrested the developer of Kratos, a global phishing-as-a-service operation, disrup...
Germany-U.S. Kratos PhaaS takedown and developer arrest
Law EnforcementAbout this happening: Authorities in Germany and the U.S. seized more than 200 servers and arrested the developer of Kratos, a global phishing-as-a-service operation, disrup...
Timeline
-
02.09.2026 12:10 1 articles · 1h ago
Aktulaev makes initial federal court appearance in San Francisco
Legal Policy Action UpdateSearzhudin Tamirlanovich Aktulaev made his initial appearance in federal court in San Francisco on August 31 after being extradited from Cyprus on August 28, and he was remanded to federal custody.
Show sources
- Extradited Russian Hacker Faces Charges Over Excel Malware Campaign That Infected Thousands — thehackernews.com — 02.09.2026 12:10
-
02.09.2026 12:06 2 articles · 1h ago
California federal grand jury indicts Russian national over freelancer phishing campaign
Initial DisclosureA California federal grand jury indicted Russian national Searzhudin Tamirlanovich Aktulaev for a phishing campaign that targeted an unnamed freelance employment technology company and infected 80,000 freelancers with malicious Microsoft Excel attachments. The allegations say he used 255 fake user accounts between June 2016 and November 2017, deployed TVRAT and DarkVNC to gain remote control over victim systems, and stole e-commerce login credentials and personally identifiable information.
Show sources
- US charges Russian for infecting 80,000 freelancers with malware — www.bleepingcomputer.com — 02.09.2026 12:06
- US charges Russian for infecting 80,000 freelancers with malware — www.bleepingcomputer.com — 02.09.2026 12:06