A Russian national has faced extradition to the United States amid serious accusations surrounding his involvement in a malware distribution scheme that allegedly targeted around 80,000 users of a popular freelance employment platform. The individual, identified as Searzhudin Tamirlanovich Aktulaev, aged 40, was apprehended in Cyprus in May 2025 and subsequently extradited on August 28, 2026. Following his extradition, Aktulaev made his initial federal court appearance in San Francisco on August 31 and was placed in federal custody.
The United States Department of Justice (DoJ) released a statement confirming that a federal grand jury had indicted Aktulaev on several charges. These include conspiracy, computer damage, unauthorized access, and aggravated identity theft, among other offenses. The allegations present a concerning picture of a systematic and potentially highly damaging operation exploiting the vulnerabilities inherent in online freelance platforms.
### Allegations of Malware Distribution
According to the indictment, Aktulaev, in conjunction with alleged co-conspirators, utilized approximately 255 fake accounts on the messaging platform associated with the well-known freelance employment website in Northern California. Through these accounts, they purportedly disseminated malicious Microsoft Excel attachments from June 2016 to November 2017. When recipients opened these attachments, they were prompted to run a macro, which subsequently downloaded malware from the internet onto their devices.
Prosecutors revealed that the malware campaign deployed various families of malware, notably a variant of the TeamViewer Remote Access Trojan (TVRAT), also known as TVSPY or TeamSpy. This particular malware exploited vulnerabilities within TeamViewer, enabling it to seize remote control over the infected computers. In conjunction with TVRAT, another malware variant named DarkVNC provided similar remote control functionality through VNC Viewer. Both types of remote access trojans were designed to transmit stolen data back to command-and-control (C2) servers, where, as alleged by prosecutors, this data was collated for fraudulent activities and other criminal schemes.
The indictment noted that the C2 domains utilized for these malicious operations were paid for using virtual currency, further complicating tracking efforts. Alarmingly, thousands of computers infected with TVRAT were reported to be communicating with a C2 domain that was hosted within the United States.
### Impact on Victims
Of significant concern is the widespread impact of these alleged actions on victims, particularly in the United States. Prosecutors indicated that approximately half of the victims resided in the U.S., with a substantial concentration in Northern California. Investigators discovered a database linked to the C2 domain that detailed thousands of victims affected by the malware. A shared document associated with an email account used for these illicit activities reportedly contained e-commerce login credentials and personally identifiable information (PII) for hundreds of additional individuals.
Should Aktulaev be convicted, he faces severe consequences. The charges of conspiracy to commit wire fraud could lead to a maximum of 20 years in prison, while other charges related to the transmission of harmful code to protected computers could result in up to 10 years of imprisonment. Additionally, for each count of aggravated identity theft, a consecutive two-year sentence could be applied. Aside from potential imprisonment, he could also be subjected to fines, including amounts reaching $250,000 or twice the gross gain from his alleged criminal activities.
The investigation has been led by the Federal Bureau of Investigation (FBI), and the successful extradition of Aktulaev was facilitated by the DoJ’s Office of International Affairs, showcasing the international collaboration for cybercrime prosecution. Currently, Aktulaev remains in federal custody, awaiting a status conference scheduled for October 5.
It is essential to note that the indictment is not indicative of guilt; it merely alleges that crimes have been committed and that Aktulaev is presumed innocent until proven guilty beyond a reasonable doubt. As the case unfolds, it emphasizes the vital need for robust cybersecurity measures and the persistent efforts to combat cybercrime on an international scale.
