Searzhudin Tamirlanovich Aktulaev, a Russian national extradited to the United States from Cyprus, appeared in a San Francisco federal court this week to face criminal charges over a massive TVRAT malware campaign targeting freelance workers. First indicted under seal in 2021, Aktulaev was apprehended in Cyprus in May 2025 before being handed over to federal authorities. He now faces a maximum sentence of 20 years in prison for running a multi-year cybercrime operation that compromised more than 80,000 computers worldwide.
Extradition and Federal Charges
Aktulaev’s indictment details a long-running intrusion scheme operating between June 2016 and November 2017. During this window, Aktulaev weaponized the internal messaging infrastructure of a major freelance employment platform to deliver malicious software directly to job seekers and contractors.
Federal prosecutors in California charged Aktulaev with conspiracy, aggravated identity theft, and the intentional transmission of code and commands to cause damage to protected computers. Following his extradition to San Francisco, Aktulaev remains in federal custody with his next court hearing scheduled for October 5. While the official indictment document remains sealed and federal authorities have omitted the exact identity of the targeted freelance platform, court disclosures confirm that approximately half of the 80,000 infected devices were located in the United States, with a heavy concentration in California.
Anatomy of the TVRAT Malware Campaign
The operation relied on systematic platform abuse and social engineering tailored to the gig economy. Aktulaev created 255 fraudulent client accounts on the freelance marketplace. Using these fake personas, he initiated direct contact with unsuspecting freelancers under the guise of offering job opportunities or discussing project contracts.
Attached to these outbound messages were weaponized Microsoft Excel files. When prospective freelancers opened the attachments, the spreadsheets displayed prompts urging users to enable content or perform specific interaction steps—a classic execution vector that triggered background scripts to retrieve and install payload binaries.
The core payloads utilized in the operation were TVRAT and DarkVNC:
- TVRAT (TVSPY / TeamSpy): A specialized remote access trojan designed to hijack legitimate installations or bundled instances of TeamViewer. Once deployed, TVRAT manipulates TeamViewer’s administrative control hooks, granting the threat actor full remote GUI control, file transfer capability, and background access without triggering visible session notifications to the victim.
- DarkVNC: A parallel remote administration tool variant designed to abuse Virtual Network Computing (VNC) protocols and VNC Viewer software. DarkVNC establishes hidden graphical desktop sessions, allowing the operator to interact with the victim machine in real time without interrupting the active user’s visible session.
Once an endpoint was compromised, Aktulaev maintained persistent access via dedicated command-and-control (C2) domains. These C2 channels allowed him to monitor victim activity over extended periods, exfiltrate sensitive files, and harvest credentials. Search warrants and evidentiary collections revealed that Aktulaev maintained central databases containing stolen e-commerce login credentials and personally identifiable information (PII) belonging to hundreds of victims.
Why Freelance Platforms Present High-Value Target Vectors
The tactical success of the campaign highlights a structural vulnerability inherent to online labor marketplaces and freelance portals. In traditional corporate environments, inbound attachments from unverified external senders face rigorous email security gateway inspection, sandbox detentions, and strict perimeter controls.
In contrast, freelance platforms connect independent contractors directly with external, unvetted clients. The primary workflow of these platforms inherently requires the exchange of project briefs, technical specifications, financial estimates, and sample documents—frequently in common business formats such as Microsoft Office files or PDFs. Freelancers, operating as solo entities without enterprise-grade security defenses or security operations center (SOC) monitoring, face strong economic incentives to open prospective client attachments promptly.
By abusing platform messaging channels, threat actors bypass traditional perimeter email filters, leveraging the native trust users place in official platform interfaces. When combined with RAT payloads that piggyback on legitimate administrative tools like TeamViewer and VNC, attackers effectively evade basic antivirus detections that might otherwise flag unknown, standalone backdoor executables.
Endpoint Risk and Security Countermeasures
Mitigating attacks that weaponize legitimate remote administration utilities requires layered defensive controls across both application software and network perimeters.
- Macro and Execution Controls: Organizations and independent professionals should enforce strict Office trust center settings, blocking macros in files originating from external or internet-delivered sources (Mark-of-the-Web). Disabling legacy DDE and dynamic script execution in productivity suites removes the primary execution path for spreadsheet-based droppers.
- Remote Access Tool Monitoring: Security operations teams must monitor endpoint environments for unauthorized installations or standalone instances of
TeamViewer.exeand VNC service binaries. Legitimate remote management utilities should be centrally deployed, digitally signed, and restricted via Application Control / AppLocker policies to prevent unauthorized side-loading or DLL hijacking. - C2 Communication Detection: Threat hunting teams should evaluate egress traffic for persistent connections to uncharacterized dynamic DNS domains or external IP addresses establishing VNC or TeamViewer control channels outside established enterprise management boundaries.
- Platform Security Enforcement: Freelance marketplaces must implement server-side sandboxing and file detonation on all attachments uploaded to internal messaging systems, analyzing Office documents for embedded macros, obfuscated scripts, and external network calls prior to delivering files to recipients.
Related content
Extradited Russian Hacker Charged Over Mass Excel Macro Campaign
Security NewsInside a Post-Breach Intrusion: SQL Injection, BadIIS, and Evasion Techniques
Security NewsNew Dolphin X Malware Uses AI to Profile and Rank High-Value Targets
Security NewsDOUBLECUP ClickFix Service Hides Malware in Browser Cache Steganography
Found something similar in your stack?
Let's find out before it becomes an incident.
Book an advisory call