Russian national indicted in malware phishing campaign

 

Russian national indicted in malware phishing campaign

US authorities have indicted a Russian national accused of running a phishing campaign that infected thousands of freelancers with malware.

Searzhudin Tamirlanovich Aktulaev, 40, was arrested in Cyprus in May 2025 and later extradited to the United States. He is accused of targeting about 80,000 freelancers between 2016 and 2017 through an online messaging platform used by a freelance employment company.

According to court documents, Aktulaev used 255 fake accounts to send Microsoft Excel files containing malicious macros. The files installed TVRAT and DarkVNC malware on victims' computers.

The malware allowed attackers to remotely control infected devices and steal information, including login details and personal data. About half of the infected computers were located in the United States.

Aktulaev is currently in federal custody and is scheduled to appear before US District Judge on October 5.

In a separate action, international law enforcement agencies and private companies have taken down parts of the Sality malware botnet that has been active for over 20 years. Authorities in the US and Europe seized related domains, while CrowdStrike helped disrupt its peer-to-peer control system and isolate infected devices.

Sality has infected more than 15,000 devices since 2003 and is linked to a cybercriminal group known as SALTY SPIDER, believed to operate from Russia.

Back to the list