Find notable cyber news and cases, enriched with sources, timelines, and signals.

TVRAT and DarkVNC phishing infection activity

Malware Activity
First reported
Last updated
Happening score
H score 34
2 unique sources, 2 articles

Summary

Hide ▲

TVRAT and DarkVNC powered a phishing malware operation that used 255 fake accounts on a freelance platform to send malicious Microsoft Excel attachments with macros to about 80,000 users in 2016-2017. The campaign delivered malware that enabled remote control of infected computers through TeamViewer and VNC Viewer, and it also supported data theft. Court records tie the activity to a Russian national, Searzhudin Tamirlanovich Aktulaev, who was extradited from Cyprus and charged in the Northern District of California.

Related Happenings

Aktulaev federal indictment and extradition for phishing-malware scheme

Law Enforcement
H score32 First: 02.09.2026 12:06 Last: 02.09.2026 12:06 Sources 1

How related: The U.S. Department of Justice (DoJ) has charged a Russian national, extradited from Cyprus on August 28, with using roughly 255 fake accounts on a freelance platform to send malware-laced Excel attachments to about 80,000 of its users in 2016 and 2017.

About this happening: The DoJ charged Searzhudin Tamirlanovich Aktulaev after his extradition from Cyprus and arrest in May 2025, alleging a 2016-2017 phishing-and-malware campaign...

Aktulaev fake-account freelancer phishing campaign

Campaign
H score40 First: 02.09.2026 12:06 Last: 02.09.2026 12:06 Sources 1

How related: The U.S. Department of Justice (DoJ) has charged a Russian national, extradited from Cyprus on August 28, with using roughly 255 fake accounts on a freelance platform to send malware-laced Excel attachments to about 80,000 of its users in 2016 and 2017.

About this happening: Searzhudin Tamirlanovich Aktulaev was charged by the DoJ over a 2016-2017 phishing campaign that used roughly 255 fake accounts on a freelance platform to send mal...

Latest development: 02.09.2026 12:10

Searzhudin Tamirlanovich Aktulaev made his initial appearance in federal court in San Francisco on August 31 after being extradited from Cyprus on August 28, and he was remanded to federal custody.

Jewelbug pairs espionage with industrial-scale cryptocurrency fraud

Threat Actor Meta
H score62 First: 13.08.2026 21:15 Last: 13.08.2026 21:15 Sources 1

About this happening: Jewelbug is a China-linked threat actor operating a blended espionage and cryptocurrency fraud ecosystem. Broadcom’s Symantec and Carbon Black Threat Hunter...

Midnight Blizzard CaptiveCrunch hospitality Wi-Fi phishing campaign

Campaign
H score37 First: 04.08.2026 03:17 Last: 04.08.2026 03:17 Sources 1

About this happening: Microsoft linked CaptiveCrunch to Midnight Blizzard / APT29, a global operation that abuses hospitality Wi‑Fi to steal Microsoft 365 accounts and deliver malware....

Germany-U.S. Kratos PhaaS takedown and developer arrest

Law Enforcement
H score39 First: 22.07.2026 02:07 Last: 22.07.2026 02:07 Sources 1

About this happening: Authorities in Germany and the U.S. seized more than 200 servers and arrested the developer of Kratos, a global phishing-as-a-service operation, disrup...

Timeline

  1. 02.09.2026 12:06 3 articles · 1h ago

    US indicts Searzhudin Tamirlanovich Aktulaev over TVRAT and DarkVNC phishing campaign

    Initial Disclosure

    A California federal grand jury indicted Russian national Searzhudin Tamirlanovich Aktulaev over a phishing campaign against an unnamed freelance employment technology company and thousands of freelancers in the Northern District of California. The conduct described in court records filed in June 2021 and unsealed this week included 255 fake user accounts, malicious Microsoft Excel attachments with macros, TVRAT also known as TeamSPy and TVSPY, DarkVNC, remote control via TeamViewer and VNC Viewer, and theft of e-commerce login credentials and personally identifiable information. Aktulaev had previously been arrested at Larnaca Airport in Cyprus and extradited to the United States in May 2025.

    Show sources