Russian man charged with infecting 80,000 freelancers through fake Excel attachments
Searzhudin Aktulaev allegedly used 255 fake accounts on a freelance work platform to spread TVRAT and DarkVNC remote-control malware between 2016 and 2017.

Key points
- A California federal grand jury has indicted 40-year-old Russian national Searzhudin Tamirlanovich Aktulaev for a phishing campaign that ran from June 2016 to November 2017.
- Aktulaev allegedly used 255 fake accounts on an unnamed freelance work platform to send booby-trapped Excel files to 80,000 freelancers.
- The attacks installed TVRAT and DarkVNC, two remote-control tools that let the attacker watch and operate victims' computers.
- Roughly half of the infected victims were based in the United States, many in the Northern District of California.
- Aktulaev was arrested at Larnaca Airport in Cyprus in May 2025, extradited to the US, and is due in court on 5 October.
A Russian man has been charged in California with running a phishing scheme, the practice of sending fake messages to trick people into opening harmful files, that infected an estimated 80,000 freelancers around the world.
Searzhudin Tamirlanovich Aktulaev, 40, was arrested at Larnaca Airport in Cyprus in May 2025 and later flown to the United States. The indictment, first filed in June 2021, was unsealed this week and first reported by BleepingComputer.
Prosecutors say the campaign ran from June 2016 to November 2017. Aktulaev allegedly set up 255 fake profiles on an unnamed freelance work platform and messaged users with Microsoft Excel attachments. The files contained macros, small pieces of automation code inside Office documents, which quietly downloaded malware onto the target's computer when opened.
What did the malware actually do?
It handed the attacker a live seat at the victim's keyboard. The two tools involved, TVRAT (also called TeamSPy or TVSPY) and DarkVNC, are remote-control programs. They piggyback on the same technology that IT support teams use to fix your laptop from another city.
TVRAT abuses TeamViewer. DarkVNC abuses VNC, another legitimate remote-desktop tool. Once installed, both quietly phoned home to a command-and-control server, the machine an attacker uses to send orders to infected computers, and shipped back stolen data.
According to the Department of Justice, Aktulaev and others used that stolen data "to commit fraud or other criminal activity." The stash included e-commerce login details and personal information such as names and addresses. The command-and-control domains were paid for in cryptocurrency, and one of them was hosted inside the United States.
Who was hit?
Freelancers, mostly. About half of the 80,000 infected users were in the US, with a heavy cluster in the Northern District of California, which is why the case landed there.
Freelance workers are a soft target for this kind of scam. They expect unsolicited messages from strangers offering work, and they routinely open spreadsheets, briefs and invoices from people they have never met. A fake job offer with an Excel attachment fits the daily inbox perfectly.
The key facts
| Detail | Figure |
|---|---|
| Charged | Searzhudin Tamirlanovich Aktulaev, 40 |
| Attack period | June 2016 to November 2017 |
| Fake accounts used | 255 |
| Freelancers targeted | 80,000 |
| Arrested | Larnaca Airport, Cyprus, May 2025 |
| Next court date | 5 October, before Judge Donato |
Would multi-factor authentication have helped?
Honestly, not directly. This attack stole session data and credentials from the machine itself once the victim opened the file, so a second login code sent by text would not have stopped the initial infection. Multi-factor authentication, meaning a second check on top of a password, still would have limited the damage on the accounts that later got reused for fraud. Attackers with stolen usernames and passwords hit a wall when there is a second factor they cannot phish out of a spreadsheet.
The real defence here sits earlier in the chain: turn off Office macros by default, treat unsolicited attachments from new clients as suspicious, and run untrusted files inside a sandbox or a throwaway account.
The Justice Department also said this week that it is working with international partners to take down the infrastructure behind the Russian-linked Sality botnet, a separate but related crackdown on long-running malware networks.



