TVRAT and DarkVNC phishing infection activity
Malware Activity
Summary
Hide ▲
Show ▼
TVRAT and DarkVNC powered a phishing malware operation that used 255 fake accounts on a freelance platform to send malicious Microsoft Excel attachments with macros to about 80,000 users in 2016-2017. The campaign delivered malware that enabled remote control of infected computers through TeamViewer and VNC Viewer, and it also supported data theft. Court records tie the activity to a Russian national, Searzhudin Tamirlanovich Aktulaev, who was extradited from Cyprus and charged in the Northern District of California.
Related Happenings
Aktulaev federal indictment and extradition for phishing-malware scheme
Law Enforcement
H score32
First: 02.09.2026 12:06
Last: 02.09.2026 12:06
Sources 1
How related:
The U.S. Department of Justice (DoJ) has charged a Russian national, extradited from Cyprus on August 28, with using roughly 255 fake accounts on a freelance platform to send malware-laced Excel attachments to about 80,000 of its users in 2016 and 2017.
About this happening:
The DoJ charged Searzhudin Tamirlanovich Aktulaev after his extradition from Cyprus and arrest in May 2025, alleging a 2016-2017 phishing-and-malware campaign...
Aktulaev federal indictment and extradition for phishing-malware scheme
Law EnforcementHow related: The U.S. Department of Justice (DoJ) has charged a Russian national, extradited from Cyprus on August 28, with using roughly 255 fake accounts on a freelance platform to send malware-laced Excel attachments to about 80,000 of its users in 2016 and 2017.
About this happening: The DoJ charged Searzhudin Tamirlanovich Aktulaev after his extradition from Cyprus and arrest in May 2025, alleging a 2016-2017 phishing-and-malware campaign...
Aktulaev fake-account freelancer phishing campaign
Campaign
H score40
First: 02.09.2026 12:06
Last: 02.09.2026 12:06
Sources 1
How related:
The U.S. Department of Justice (DoJ) has charged a Russian national, extradited from Cyprus on August 28, with using roughly 255 fake accounts on a freelance platform to send malware-laced Excel attachments to about 80,000 of its users in 2016 and 2017.
About this happening:
Searzhudin Tamirlanovich Aktulaev was charged by the DoJ over a 2016-2017 phishing campaign that used roughly 255 fake accounts on a freelance platform to send mal...
Aktulaev fake-account freelancer phishing campaign
CampaignHow related: The U.S. Department of Justice (DoJ) has charged a Russian national, extradited from Cyprus on August 28, with using roughly 255 fake accounts on a freelance platform to send malware-laced Excel attachments to about 80,000 of its users in 2016 and 2017.
About this happening: Searzhudin Tamirlanovich Aktulaev was charged by the DoJ over a 2016-2017 phishing campaign that used roughly 255 fake accounts on a freelance platform to send mal...
Latest development: 02.09.2026 12:10
Searzhudin Tamirlanovich Aktulaev made his initial appearance in federal court in San Francisco on August 31 after being extradited from Cyprus on August 28, and he was remanded to federal custody.
Jewelbug pairs espionage with industrial-scale cryptocurrency fraud
Threat Actor Meta
H score62
First: 13.08.2026 21:15
Last: 13.08.2026 21:15
Sources 1
About this happening:
Jewelbug is a China-linked threat actor operating a blended espionage and cryptocurrency fraud ecosystem. Broadcom’s Symantec and Carbon Black Threat Hunter...
Jewelbug pairs espionage with industrial-scale cryptocurrency fraud
Threat Actor MetaAbout this happening: Jewelbug is a China-linked threat actor operating a blended espionage and cryptocurrency fraud ecosystem. Broadcom’s Symantec and Carbon Black Threat Hunter...
Midnight Blizzard CaptiveCrunch hospitality Wi-Fi phishing campaign
Campaign
H score37
First: 04.08.2026 03:17
Last: 04.08.2026 03:17
Sources 1
About this happening:
Microsoft linked CaptiveCrunch to Midnight Blizzard / APT29, a global operation that abuses hospitality Wi‑Fi to steal Microsoft 365 accounts and deliver malware....
Midnight Blizzard CaptiveCrunch hospitality Wi-Fi phishing campaign
CampaignAbout this happening: Microsoft linked CaptiveCrunch to Midnight Blizzard / APT29, a global operation that abuses hospitality Wi‑Fi to steal Microsoft 365 accounts and deliver malware....
Germany-U.S. Kratos PhaaS takedown and developer arrest
Law Enforcement
H score39
First: 22.07.2026 02:07
Last: 22.07.2026 02:07
Sources 1
About this happening:
Authorities in Germany and the U.S. seized more than 200 servers and arrested the developer of Kratos, a global phishing-as-a-service operation, disrup...
Germany-U.S. Kratos PhaaS takedown and developer arrest
Law EnforcementAbout this happening: Authorities in Germany and the U.S. seized more than 200 servers and arrested the developer of Kratos, a global phishing-as-a-service operation, disrup...
Timeline
-
02.09.2026 12:06 3 articles · 1h ago
US indicts Searzhudin Tamirlanovich Aktulaev over TVRAT and DarkVNC phishing campaign
Initial DisclosureA California federal grand jury indicted Russian national Searzhudin Tamirlanovich Aktulaev over a phishing campaign against an unnamed freelance employment technology company and thousands of freelancers in the Northern District of California. The conduct described in court records filed in June 2021 and unsealed this week included 255 fake user accounts, malicious Microsoft Excel attachments with macros, TVRAT also known as TeamSPy and TVSPY, DarkVNC, remote control via TeamViewer and VNC Viewer, and theft of e-commerce login credentials and personally identifiable information. Aktulaev had previously been arrested at Larnaca Airport in Cyprus and extradited to the United States in May 2025.
Show sources
- US charges Russian for infecting 80,000 freelancers with malware — www.bleepingcomputer.com — 02.09.2026 12:06
- US charges Russian for infecting 80,000 freelancers with malware — www.bleepingcomputer.com — 02.09.2026 12:06
- Extradited Russian Hacker Faces Charges Over Excel Malware Campaign That Infected Thousands — thehackernews.com — 02.09.2026 12:10