Russian extradited for Freelancer malware
A Russian national extradited from Cyprus faces US charges for allegedly using fake freelance accounts to distribute malware to around 80,000 users.

A Russian man has been extradited to the United States to face charges for his alleged role in a malware campaign that targeted approximately 80,000 users of a freelance employment platform. The US Department of Justice states that Searzhudin Tamirlanovich Aktulaev, 40, was arrested in Cyprus in May 2025 and extradited on August 28, 2026.
According to a federal indictment, Aktulaev and co-conspirators used roughly 255 fake accounts on the messaging system of a major freelance company based in Northern California. Between June 2016 and November 2017, these accounts sent malicious Microsoft Excel file attachments to users. Opening the files prompted recipients to enable a macro, which then downloaded malware from the internet.
Malware Families Used in the Attack
The campaign allegedly deployed two distinct families of remote access trojans (RATs). Both were designed to steal data and send it to command-and-control (C2) servers for use in fraud and other crimes.
A variant of TVRAT, also known as TVSPY or TeamSpy, exploited a vulnerability in TeamViewer software to grant attackers remote control. DarkVNC provided similar access through VNC Viewer. Prosecutors allege the C2 infrastructure was paid for with virtual currency, and thousands of computers infected with TVRAT were communicating with a US-hosted C2 domain.
Scale of the Compromise and Victim Data
Approximately half of the estimated 80,000 victims were located in the United States, with many in the Northern District of California. Investigators found a database on a seized C2 server that contained information on thousands of victims. A separate document from an email account linked to the alleged activity held e-commerce login credentials and personally identifiable information for hundreds more individuals.
The Federal Bureau of Investigation led the inquiry. The DoJ's Office of International Affairs handled the extradition. Aktulaev made an initial court appearance in San Francisco on August 31, 2026, and was remanded to federal custody. A status conference is scheduled for October 5.
Potential Penalties if Convicted
If found guilty, Aktulaev faces significant prison time. The indictment charges him with conspiracy, computer damage, unauthorized access, and aggravated identity theft, among other offenses. The DoJ notes the maximum penalties include 20 years for conspiracy to commit wire fraud, 10 years for transmitting code to damage protected computers, and a mandatory two-year consecutive sentence for each count of aggravated identity theft. Fines could reach $250,000 or twice the gross gain from the alleged crimes.
The Department of Justice emphasizes that an indictment contains only allegations. Searzhudin Tamirlanovich Aktulaev is presumed innocent unless proven guilty in court beyond a reasonable doubt.





