The U.S. Department of Justice (DoJ) has charged a Russian national, extradited from Cyprus on August 28, with using roughly 255 fake accounts on a freelance platform to send malware-laced Excel attachments to about 80,000 of its users in 2016 and 2017.
Searzhudin Tamirlanovich Aktulaev, 40, was arrested in Cyprus in May 2025, the U.S. Attorney’s Office for the Northern District of California said in a press release. He made his initial appearance in federal court in San Francisco on August 31 and was remanded to federal custody.
The indictment, filed on June 1, 2021, and unsealed the same day as his appearance, describes the platform only as “a well-known freelance employment technology company” based in the Northern District of California.
Thousands of computers infected with TVRAT, one of two malware types named in the indictment, were calling back to a command-and-control (C2) domain hosted in the U.S., with approximately half of the victims located in the country, many of them in the district.
A shared document in the email account used in the scheme contained e-commerce login credentials and personally identifiable information (PII) for hundreds of victims.
Aktulaev is charged with conspiracy to commit wire fraud; transmission of a program, information, code, or command to cause damage to protected computers; conspiracy to commit computer fraud; unauthorized access to a protected computer to obtain information for financial gain and to obtain value; and aggravated identity theft.


Leave a Reply