Russian National Indicted in U.S. for Malware Campaign Targeting Freelancers
AI-generated from multiple sources. Verify before acting on this reporting.
SAN FRANCISCO — Additional corroborating reports have emerged regarding the ongoing investigation into Searzhudin Tamirlanovich Aktulaev. These new accounts provide further details on the scope of the phishing campaign targeting independent contractors globally. The fresh information reinforces the allegations that Aktulaev orchestrated the deployment of TVRAT and DarkVNC malware to steal sensitive data and facilitate fraud. While the original indictment outlined the initial charges, these subsequent reports expand the understanding of the operation's reach and impact across various sectors. Law enforcement continues to analyze the expanded data as part of the broader effort to dismantle the network responsible for infecting thousands of freelancers with malicious software.
SAN FRANCISCO — A Russian national was indicted by a federal grand jury in Northern California on Wednesday for orchestrating a phishing campaign that infected thousands of freelancers with malicious software designed to steal sensitive data and facilitate fraud.
Searzhudin Tamirlanovich Aktulaev, identified as a citizen of Russia, faces charges related to the deployment of TVRAT and DarkVNC malware. The indictment alleges that Aktulaev targeted independent contractors globally, using deceptive emails to trick victims into downloading the code. Once installed, the software granted attackers remote access to infected computers, allowing them to harvest credentials, financial information, and other personal data.
The charges were unsealed in the U.S. District Court for the Northern District of California on September 2, 2026. Federal prosecutors stated that the operation was part of a broader effort to commit fraud and engage in criminal activity by compromising the digital security of freelance workers who often handle sensitive client information.
Aktulaev is currently believed to be in custody following an arrest in Cyprus. Authorities in the island nation detained the suspect, paving the way for potential extradition proceedings to the United States. The indictment details how the malware functioned as a remote access trojan, enabling operatives to monitor screen activity, record keystrokes, and execute commands on victim machines without their knowledge.
The scale of the campaign reportedly affected thousands of individuals across various industries who rely on digital platforms for their livelihoods. Victims were allegedly lured through phishing links that mimicked legitimate job portals or communication tools commonly used by freelancers. The stolen data was subsequently used to access bank accounts, commit identity theft, and launch further cyberattacks.
Federal officials emphasized the threat posed by such campaigns to the global gig economy, noting that freelancers often lack the robust cybersecurity infrastructure available to larger corporations. The use of DarkVNC, a tool frequently associated with advanced persistent threats, suggests a sophisticated level of technical capability behind the operation.
As legal proceedings move forward, questions remain regarding the full extent of the data breach and whether other individuals were involved in the network. U.S. authorities have not yet disclosed if Aktulaev acted alone or as part of a larger criminal syndicate. Additionally, it remains unclear how many victims have been fully restored to their pre-infection status or if further financial losses are expected to emerge.
The case highlights the increasing targeting of independent workers by state-sponsored and non-state cybercriminal groups seeking to exploit vulnerabilities in decentralized workforces. Prosecutors indicated that Aktulaev faces significant penalties if convicted, including lengthy prison terms and substantial fines under federal computer fraud statutes.