A Russian citizen faces up to 20 years in prison after a federal grand jury in California indicted him for a phishing campaign that infected more than 80,000 computers. Searzhudin Tamirlanovich Aktulaev was extradited to the United States in August 2026 following a five-year pursuit that began with his arrest in Cyprus in May 2021. The indictment, filed in June 2021 and unsealed in September 2026, accuses him of using TVRAT (TeamViewer Remote Access Trojan) and DarkVNC malware to steal victims' data. The FBI conducted the investigation and the case is being prosecuted in the Northern District of California.

What You Need to Know

This case highlights the ongoing threat of phishing attacks that exploit legitimate remote access tools to gain full control of victims' systems. The malware used, TVRAT and DarkVNC, allowed attackers to steal credentials and personal data from freelancers on a job platform. The scale of 80,000 compromised computers shows how a single coordinated campaign can affect thousands of individuals across the United States.

The Phishing Campaign

According to the indictment, Aktulaev exploited the online message platform of a well-known freelancer employment company based in the Northern District of California. He sent malicious Microsoft Excel attachments using approximately 255 fake user accounts. When victims opened the attachments and enabled macros, the malware downloaded onto their systems. Roughly half of the victims were in the United States, with many residing in the Northern District of California.

The attack used a command-and-control domain hosted in the United States, paid for with virtual currency. A database on that domain revealed thousands of victims. Investigators also found a shared document on the email account used in the criminal activities that contained e-commerce login credentials and personally identifiable information for hundreds of victims.

Remote Access Malware Overview

The malware deployed in this campaign gives attackers complete remote control over infected computers. TVRAT exploits the popular remote desktop tool TeamViewer, while DarkVNC targets VNC Viewer. Both tools are widely used for legitimate remote administration, making them effective vectors for cybercriminals.

  • TVRAT: Exploits TeamViewer to grant attackers remote control over infected systems, allowing data theft and further malicious activity.
  • DarkVNC: Uses VNC Viewer to access victims' desktops, enabling direct observation and file exfiltration.
  • Data exfiltration: Stolen information is sent to a command-and-control server where attackers extract it for fraud and identity theft.

Why This Matters

This indictment demonstrates that international law enforcement can pursue cybercriminals across borders, even years after the crimes occur. Aktulaev was arrested in Cyprus in 2021 and extradited in 2026, a process that signals long-term commitment to accountability. For freelancers and remote workers, the case serves as a reminder that seemingly legitimate email attachments from trusted platforms can hide sophisticated malware. The potential 20-year sentence, combined with fines and asset forfeiture, may deter similar attacks in the future. The FBI's investigation also underscores the increasing frequency of large-scale credential theft campaigns that target the growing remote workforce.

Ongoing Investigations

The FBI continues to investigate related cybercrime incidents. In a separate case, the agency is probing the leak of 153 million US and Canadian drivers' licenses on a Russian cybercrime forum. That breach, which reportedly included the license of the US Secretary of Defense, involved a data authentication service provider, highlighting the broad scope of identity theft threats facing individuals and governments alike.