United States Attorney's Office for the Northern District of California

09/01/2026 | Press release | Distributed by Public on 09/01/2026 19:09

Russian National Indicted For Exploiting Online Platform Used For Freelance Employment And Distributing Malware To Thousands Of Victim Users Worldwide For Financial Gain

SAN FRANCISCO - A federal grand jury has indicted Searzhudin Tamirlanovich Aktulaev on charges of Conspiracy, Transmission of a Program, Information, Code, and Command to Cause Damage to a Protected Computer, and Aggravated Identity Theft, among other offenses. Defendant was arrested in Cyprus in May 2025 and has been extradited to the United States. Yesterday, he made his initial appearance in federal court in San Francisco, and he was remanded to federal custody.

According to the indictment filed June 1, 2021, and unsealed yesterday, Aktulaev, 40 years old, and a national of the Russian Federation, conspired to exploit the online message platform of a well-known freelance employment technology company, located in the Northern District of California, to spread malware to approximately 80,000 of their freelance users between at least June 2016 through November 2017. The messages, which were sent from approximately 255 fake user accounts, contained malicious Microsoft Excel attachments. When opened, the attachments prompted users to run a macro, which then downloaded malware from the Internet.

The indictment alleges Aktulaev's use of two types of malware. One was a variant of the "TVRAT" (TeamViewer Remote Access Trojan) malware, also known as "TVSPY" or "TeamSpy." According to the allegations, TVRAT exploits a vulnerability in the popular remote administration tool TeamViewer to provide the subjects with remote control over the infected computer. The other malware, called "DarkVNC," is similar in functionality to TVRAT except that instead of TeamViewer, it exploits the remote administration tool VNC Viewer. Both TVRAT and DarkVNC malware sent stolen data from a victim computer to a command-and-control server, from which the stolen data was collected and used by Aktulaev and his co-conspirators to commit fraud or other criminal activity.

As described in the indictment, the command-and-control domains were paid for using virtual currency, and thousands of computers infected by the TVRAT malware were "calling back" to a command-and-control domain hosted in the United States. According to the indictment, approximately half of the victims were in the United States, many of whom were located in the Northern District of California. A database found on the command-and-control domain revealed thousands of victims. Additionally, a shared document on the email account used in the criminal activities contained information to include e-commerce login credentials, as well as personally identifiable information ("PII") for hundreds of victims.

United States Attorney Craig H. Missakian and Special Agent in Charge Scott R. Schelble made the announcement.

Aktulaev is currently in federal custody. Aktulaev is next scheduled to appear in district court on October 5, 2026 for a status conference before U.S. District Judge Donato.

An indictment merely alleges that crimes have been committed, and all defendants are presumed innocent until proven guilty beyond a reasonable doubt. If convicted, Aktulaev faces a maximum sentence of twenty years in prison and a $250,000 fine or twice the gross gain for Conspiracy to Commit Wire Fraud in violation of 18 U.S.C. § 1349; ten years in prison and a $250,000 fine or twice the gross gain for Transmission of a Program, Information, Code, and Command to Cause Damage Affecting 10 or More Protected Computers During Any 1-Year Period, in violation of 18 U.S.C. § 1030(a)(5)(A); five years in prison and a $250,000 fine or twice the gross gain for Conspiracy to Commit Computer Fraud to defraud and Obtain Value and to Cause Damage to a Protected Computer, in violation of 18 U.S.C. § 371, Unauthorized Access to Obtain Information for the Purpose of Financial Gain in violation of 18 U.S.C. § 1030(a)(2)(C), and Unauthorized Access to a Protected Computer to Obtain Value in violation of 18 U.S.C. § 1030(a)(4); and two years in prison to run consecutive to any other term imposed and a $250,000 fine or twice the gross gain for each violation of Aggravated Identity Theft in violation of 18 U.S.C. § 1028A(a)(1). Any sentence following conviction would be imposed by the court after consideration of the U.S. Sentencing Guidelines and the federal statute governing the imposition of a sentence, 18 U.S.C. § 3553.

This case is being prosecuted by the National Security, Cyber, and Special Prosecutions Section. The prosecution is the result of an investigation by the Federal Bureau of Investigation.

The Justice Department's Office of International Affairs secured the August 28, 2026 extradition of Aktulaev.

United States Attorney's Office for the Northern District of California published this content on September 01, 2026, and is solely responsible for the information contained herein. Distributed via Public Technologies (PUBT), unedited and unaltered, on September 02, 2026 at 01:09 UTC. If you believe the information included in the content is inaccurate or outdated and requires editing or removal, please contact us at [email protected]