Estimated reading time: 5 minutes · Last updated:
A Department of Justice press release says Searzhudin Tamirlanovich Aktulaev ran a phishing campaign infected 80,000 PCs between June 2016 and November 2017, using malicious Excel attachments that installed remote‑control malware. The indictment was filed in June 2021, made public in September 2026 and alleges Aktulaev operated with roughly 255 fake user accounts to target freelancers on an online message platform in the Northern District of California. Aktulaev was arrested in Cyprus in May 2021, extradited to the United States in August 2026 and made a first federal court appearance in San Francisco; he is scheduled to appear again in district court on October 5, 2026.
“conspired to exploit the online message platform of a well-known freelance employment technology company, located in the Northern District of California, to spread malware to approximately 80,000 freelancers”
Department of Justice press release
Key takeaways
- Scale of the alleged intrusion: A DOJ indictment alleges data were taken from over 80,000 computers between June 2016 and November 2017.
- Method used: Prosecutors say the campaign used about 255 fake user accounts to send Excel attachments that deployed TVRAT and DarkVNC remote‑control malware.
- Legal timeline: Aktulaev was arrested in Cyprus in May 2021, extradited in August 2026 and has a district court appearance set for October 5, 2026.
- Potential penalty: For the wire fraud conspiracy count alone he could face up to 20 years in prison and a $250,000 fine or twice the illicit gains, prosecutors say.
Table of contents
What the indictment says happened and how the malware worked
The Department of Justice indictment outlines a multi‑stage phishing operation that targeted users of a freelance employment messaging platform in the Northern District of California. Prosecutors state the campaign ran from June 2016 through November 2017 and used roughly 255 counterfeit accounts to send messages with Microsoft Excel attachments that asked recipients to enable macros. When triggered, those macros downloaded remote‑control malware that allowed attackers to take over infected machines and extract files.
The indictment identifies two malware families used in the operation: TVRAT and DarkVNC. TVRAT exploits the TeamViewer remote administration tool, while DarkVNC abuses VNC Viewer–style remote access. The complaint asserts infected machines sent stolen data to a remote-control server located in the United States; it further alleges that a database on that server and a shared document tied to the criminal email account contained e-commerce credentials and personally identifiable information for hundreds of victims.
How investigators traced operations and the scope the indictment describes
Federal investigators traced thousands of infected machines back to a U.S.-hosted command‑and‑control domain and linked withdrawals of stolen material to accounts controlled by the defendants, the DOJ statement says. Prosecutors say roughly half of the identified victims were in the United States, and many were residents of the Northern District of California; a database on the C2 domain showed thousands of victim records. The indictment further alleges the domain was paid for using virtual currency.
The Department of Justice framed those technical traces as evidence of a conspiracy to commit wire fraud and aggravated identity theft. That chain—phishing messages, macros that downloaded remote‑control tools, data exfiltration to a C2 domain, and the subsequent extraction of harvested credentials—forms the prosecutorial theory that will be tested at the upcoming court proceedings.
Legal exposure, prosecution team and the next procedural steps
The indictment, filed in June 2021 and released in September 2026, charges Searzhudin Tamirlanovich Aktulaev with conspiracy, transmission of damaging code to protected computers, aggravated identity theft and related offenses. The case is being handled by the National Security, Cyber, and Special Prosecutions Section, and the FBI led the investigation. If convicted, Aktulaev faces penalties that vary by count; prosecutors note the wire fraud conspiracy alone carries up to 20 years in prison and a $250,000 fine or twice the illegal gains, while other counts have terms ranging from two to twenty years.
Aktulaev was arrested in Cyprus in May 2021, extradited to the United States in August 2026, and made an initial federal appearance in San Francisco before being remanded to federal custody. His next district-court appearance is set for 5 October 2026, when the court is expected to address arraignment and pretrial scheduling.
What could move this either way
The case for
- The U.S. hosting of the command‑and‑control domain and the presence of a database with victim records strengthen prosecutors' technical evidence and make cross‑border collection simpler for U.S. teams.
- Extradition in August 2026 and an active federal docket give prosecutors scheduled opportunities—including the October 5, 2026 hearing—to press discovery and preserve evidence.
The case against
- The alleged operation spans multiple years and international borders, which can complicate evidence gathering, witness availability and attribution of actions to a single defendant.
- Defense challenges to forensic methods, the provenance of the database copies, or the legality of overseas collection could delay proceedings or narrow what evidence is admissible.
What to be careful about
- Freelance platform users face long‑term credential compromise and follow‑on account fraud because the indictment alleges e‑commerce logins and PII for hundreds of victims were exposed.
- The vendor or platform used in the campaign may face reputational and potential civil liability if customers' data was compromised at scale.
- Stolen credentials and PII appearing on criminal forums can produce secondary harms — account takeover, identity fraud and targeted spear‑phishing — for thousands of people.
The bottom line
The Department of Justice indictment frames the case as a large‑scale, multi‑year phishing and data‑extraction operation that exploited standard office tools and remote access software. The technical traces prosecutors describe—Excel macros leading to TVRAT and DarkVNC installations, a U.S.‑hosted command‑and‑control domain and harvested credential stores—are the evidentiary pillars the government will use at the October 5, 2026 district court appearance. Beyond the criminal case, the alleged exposure of e‑commerce credentials and PII for hundreds of people creates ongoing fraud and identity‑theft risk for victims and reputational and operational exposure for the platform implicated in the indictment.
What to watch
- October 5, 2026: Aktulaev’s scheduled district court appearance in the Northern District of California to address arraignment and pretrial scheduling.
- Watch for public DOJ or FBI updates to the separate investigation that the indictment notes into the leak of 153 million U.S. and Canadian drivers’ licenses; no date has been set for that disclosure.
Frequently asked questions
What malware did prosecutors say was used in the campaign?
The indictment names TVRAT and DarkVNC as the remote‑control malware families used; TVRAT abuses TeamViewer and DarkVNC targets VNC Viewer‑style remote access, allowing attackers to control infected machines and copy files.
How many people were affected and when did the attacks occur?
Prosecutors allege data was taken from over 80,000 computers during a campaign running from June 2016 through November 2017, with a database and shared documents showing thousands of victim records and PII for hundreds reported.
What penalties does the indictment say the defendant faces?
For the wire-fraud-conspiracy count, the Department of Justice says Searzhudin Tamirlanovich Aktulaev could face up to 20 years in prison and a $250,000 fine or an amount equal to twice the illicit gains; the other counts expose him to prison sentences ranging from two to twenty years.