The record
Written from the 1 report below. Nothing here is unsourced.
- The U.S.
- Department of Justice has charged Searzhudin Tamirlanovich Aktulaev, a 40-year-old Russian national extradited from Cyprus in August, over a malware campaign that ran from June 2016 to November 2017.
- Prosecutors say he used about 255 fake accounts on a well-known freelance platform to send roughly 80,000 users Excel attachments that, when macros were enabled, installed TVRAT and DarkVNC malware giving operators remote control of infected computers.
- Thousands of machines were infected, with about half of the victims in the United States and many in Northern California, and stolen data was used for fraud.
- Aktulaev has pleaded not guilty and, per the Russian Embassy, said he was unaware of the charges; the indictment contains allegations only and he is presumed innocent until proven guilty.
What to watch next
- Outcome of Aktulaev's federal court proceedings in San Francisco following his remand to custody.
- Whether the freelance platform is publicly identified and if it discloses further details about victims.
- Continued use of job-hunting and freelance lures by other threat actors, as noted with Lazarus Group and Sandworm-linked campaigns.
Coverage1
1 report
English national1
All filed from India
Named United States · Cyprus · Russia · Lazarus Group · Sandworm · Avast · Check Point Research · Computer Emergency Response Team of Ukraine · ESET · Kaspersky · Microsoft · Searzhudin Tamirlanovich Aktulaev · TeamViewer
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
