What happened
The U.S. Department of Justice charged Searzhudin Tamirlanovich Aktulaev, a 40 year old Russian national, with running a malware campaign against users of a well-known freelance employment platform. Aktulaev was arrested in Cyprus in May 2025, extradited to the United States on August 28, and made his initial appearance in federal court in San Francisco on August 31. The indictment, filed in June 2021, was unsealed at his appearance.
Prosecutors allege that from at least June 2016 through November 2017, Aktulaev used roughly 255 fake accounts on the platform to send malware-laced Excel attachments to about 80,000 of its users. The attachments prompted recipients to enable a macro that downloaded malware from the internet. The campaign used two remote access tools, a TeamViewer-based trojan called TVRAT and a hidden VNC utility called DarkVNC, both of which gave operators remote control of infected machines and sent stolen data to a command-and-control server.
Thousands of infected computers called back to a command-and-control domain hosted in the United States, with roughly half the victims located there. A shared document in the email account used for the scheme held e-commerce login credentials and personally identifiable information for hundreds of victims. Aktulaev faces charges including conspiracy to commit wire fraud, computer fraud and aggravated identity theft. He has denied guilt and said he was unaware of the U.S. charges, according to statements from the Russian Embassy in Nicosia. The DOJ notes the indictment contains allegations only, and he is presumed innocent until proven guilty.
Why this is a GRC story
The attack channel matters more than the malware. Freelance and job platforms carry an implicit trust signal: messages from them look like ordinary work communication, and a recipient expecting a brief or a contract is primed to open an attachment. The scale here, 80,000 users contacted through 255 accounts, shows how platform trust can be weaponized at volume. And the pattern is current: researchers have documented North Korean hackers using the same lure against developers, and recent months saw Lazarus-linked fake job offers and a Sandworm-linked cluster contacting candidates through job-site chat.
For security teams the mitigations are familiar but worth restating. Default macro blocking for Office files downloaded from the internet, standard since 2022, would have stopped this delivery method cold. Endpoint detection that watches for remote access tools and hidden desktops covers the post-execution phase. And user awareness still matters: attachments from new contacts on freelance platforms deserve the same suspicion as attachments from strangers in email.
The case also illustrates enforcement latency. The crimes ran in 2016 and 2017, the indictment came in 2021, the arrest in 2025 and the extradition in 2026. Organizations cannot rely on enforcement to protect them from an active campaign; the defense lives in controls and user behavior.
What to watch
Watch how the case proceeds and whether it pushes platforms to tighten account verification, since 255 coordinated fake accounts is also a platform governance failure. For GRC teams the actionable thread: job and freelance channels are an established attack surface for criminals and state-sponsored groups alike, and controls over third-party communication channels should treat them accordingly.
Attribution: Analysis based on The Hacker News' reporting and related public reporting. This article is original commentary, not a repost of the source material.
