A Russian citizen faces up to 20 years in prison after a federal grand jury in California indicted him for a phishing campaign that infected more than 80,000 computers. Searzhudin Tamirlanovich Aktulaev was extradited to the United States in August 2026 following a five-year pursuit that began with his arrest in Cyprus in May 2021. The indictment, filed in June 2021 and unsealed in September 2026, accuses him of using TVRAT (TeamViewer Remote Access Trojan) and DarkVNC malware to steal victims' data. The FBI conducted the investigation and the case is being prosecuted in the Northern District of California.
The Phishing Campaign
According to the indictment, Aktulaev exploited the online message platform of a well-known freelancer employment company based in the Northern District of California. He sent malicious Microsoft Excel attachments using approximately 255 fake user accounts. When victims opened the attachments and enabled macros, the malware downloaded onto their systems. Roughly half of the victims were in the United States, with many residing in the Northern District of California.
The attack used a command-and-control domain hosted in the United States, paid for with virtual currency. A database on that domain revealed thousands of victims. Investigators also found a shared document on the email account used in the criminal activities that contained e-commerce login credentials and personally identifiable information for hundreds of victims.
Remote Access Malware Overview
The malware deployed in this campaign gives attackers complete remote control over infected computers. TVRAT exploits the popular remote desktop tool TeamViewer, while DarkVNC targets VNC Viewer. Both tools are widely used for legitimate remote administration, making them effective vectors for cybercriminals.
Why This Matters
This indictment demonstrates that international law enforcement can pursue cybercriminals across borders, even years after the crimes occur. Aktulaev was arrested in Cyprus in 2021 and extradited in 2026, a process that signals long-term commitment to accountability. For freelancers and remote workers, the case serves as a reminder that seemingly legitimate email attachments from trusted platforms can hide sophisticated malware. The potential 20-year sentence, combined with fines and asset forfeiture, may deter similar attacks in the future. The FBI's investigation also underscores the increasing frequency of large-scale credential theft campaigns that target the growing remote workforce.
Ongoing Investigations
The FBI continues to investigate related cybercrime incidents. In a separate case, the agency is probing the leak of 153 million US and Canadian drivers' licenses on a Russian cybercrime forum. That breach, which reportedly included the license of the US Secretary of Defense, involved a data authentication service provider, highlighting the broad scope of identity theft threats facing individuals and governments alike.



