Aktulaev federal indictment and extradition for phishing-malware scheme
Law Enforcement
Summary
Hide ▲
Show ▼
The DoJ charged Searzhudin Tamirlanovich Aktulaev after his extradition from Cyprus and arrest in May 2025, alleging a 2016-2017 phishing-and-malware campaign tied to an unnamed freelance employment technology company in the Northern District of California. Prosecutors say he used about 255 fake accounts to send malware-laced Microsoft Excel attachments to about 80,000 users, with the messages delivering TVRAT and DarkVNC. The alleged operation gave attackers remote control over infected computers and was used to steal e-commerce login credentials and PII for fraud and other criminal activity.
Related Happenings
Aktulaev fake-account freelancer phishing campaign
Campaign
H score40
First: 02.09.2026 12:06
Last: 02.09.2026 12:06
Sources 1
How related:
The U.S. Department of Justice (DoJ) has charged a Russian national, extradited from Cyprus on August 28, with using roughly 255 fake accounts on a freelance platform to send malware-laced Excel attachments to about 80,000 of its users in 2016 and 2017.
About this happening:
Searzhudin Tamirlanovich Aktulaev was charged by the DoJ over a 2016-2017 phishing campaign that used roughly 255 fake accounts on a freelance platform to send mal...
Aktulaev fake-account freelancer phishing campaign
CampaignHow related: The U.S. Department of Justice (DoJ) has charged a Russian national, extradited from Cyprus on August 28, with using roughly 255 fake accounts on a freelance platform to send malware-laced Excel attachments to about 80,000 of its users in 2016 and 2017.
About this happening: Searzhudin Tamirlanovich Aktulaev was charged by the DoJ over a 2016-2017 phishing campaign that used roughly 255 fake accounts on a freelance platform to send mal...
Latest development: 02.09.2026 12:10
Searzhudin Tamirlanovich Aktulaev made his initial appearance in federal court in San Francisco on August 31 after being extradited from Cyprus on August 28, and he was remanded to federal custody.
TVRAT and DarkVNC phishing infection activity
Malware Activity
H score34
First: 02.09.2026 12:06
Last: 02.09.2026 12:06
Sources 1
How related:
DarkVNC, both of which gave the operators remote control of the infected computer.
About this happening:
TVRAT and DarkVNC powered a phishing malware operation that used 255 fake accounts on a freelance platform to send malicious Microsoft Excel attachments with m...
TVRAT and DarkVNC phishing infection activity
Malware ActivityHow related: DarkVNC, both of which gave the operators remote control of the infected computer.
About this happening: TVRAT and DarkVNC powered a phishing malware operation that used 255 fake accounts on a freelance platform to send malicious Microsoft Excel attachments with m...
DoJ charges Mabna Institute members and State Department offers reward
Law Enforcement
H score70
First: 20.08.2026 20:23
Last: 20.08.2026 20:23
Sources 1
About this happening:
U.S. Department of Justice charged 17 Mabna Institute members in a cyber intrusion case tied to Iran's IRGC, and the U.S. Department of State announced a $10...
DoJ charges Mabna Institute members and State Department offers reward
Law EnforcementAbout this happening: U.S. Department of Justice charged 17 Mabna Institute members in a cyber intrusion case tied to Iran's IRGC, and the U.S. Department of State announced a $10...
Kratos ecosystem shift changes threat-actor operations
Threat Actor Meta
H score39
First: 22.07.2026 02:07
Last: 22.07.2026 02:07
Sources 1
About this happening:
The Kratos phishing-as-a-service ecosystem was dismantled after it scaled to more than 1,800 criminal customers, exposing a subscription model that drove roughly 15,000...
Kratos ecosystem shift changes threat-actor operations
Threat Actor MetaAbout this happening: The Kratos phishing-as-a-service ecosystem was dismantled after it scaled to more than 1,800 criminal customers, exposing a subscription model that drove roughly 15,000...
Germany-U.S. Kratos PhaaS takedown and developer arrest
Law Enforcement
H score39
First: 22.07.2026 02:07
Last: 22.07.2026 02:07
Sources 1
About this happening:
Authorities in Germany and the U.S. seized more than 200 servers and arrested the developer of Kratos, a global phishing-as-a-service operation, disrup...
Germany-U.S. Kratos PhaaS takedown and developer arrest
Law EnforcementAbout this happening: Authorities in Germany and the U.S. seized more than 200 servers and arrested the developer of Kratos, a global phishing-as-a-service operation, disrup...
Timeline
-
02.09.2026 12:06 3 articles · 1h ago
California federal grand jury indicts Searzhudin Tamirlanovich Aktulaev
Legal Policy Action UpdateA California federal grand jury indicted Russian national Searzhudin Tamirlanovich Aktulaev for a phishing campaign against users of an unnamed freelance employment technology company, alleging that he used 255 fake user accounts and malicious Microsoft Excel attachments with macros to reach 80,000 freelancers between June 2016 and November 2017. Prosecutors said the operation deployed TVRAT, also known as TeamSPy and TVSPY, and DarkVNC to give remote control over infected systems through TeamViewer and VNC Viewer, while stealing e-commerce login credentials and personally identifiable information and sending stolen data to command-and-control servers. Aktulaev had also been extradited to the United States after his arrest in Cyprus at Larnaca Airport in May 2025 and was in federal custody with an October 5 court appearance scheduled before U.S. District Judge Donato.
Show sources
- US charges Russian for infecting 80,000 freelancers with malware — www.bleepingcomputer.com — 02.09.2026 12:06
- US charges Russian for infecting 80,000 freelancers with malware — www.bleepingcomputer.com — 02.09.2026 12:06
- Extradited Russian Hacker Faces Charges Over Excel Malware Campaign That Infected Thousands — thehackernews.com — 02.09.2026 12:10