Malware campaign targeted freelancers with poisoned Excel files
A Russian national is staring down a potential 20-year prison sentence after being indicted for a malware campaign that infected more than 80,000 freelancers back in 2016.
Searzhudin Tamirlanovich Aktulaev made his first appearance in a San Francisco federal court on Monday. He was arrested in Cyprus in May 2025 and extradited to the U.S. last week, according to the Justice Department.
The indictment, originally filed in 2021, accuses Aktulaev of deploying a variant of the TVRAT malware — also known as TVSPY or TeamSpy — through the messaging platform of a freelance employment tech company. Between June 2016 and November 2017, he allegedly spread the malware to roughly 80,000 of the site’s users.
Prosecutors say Aktulaev sent messages from 255 fake user accounts, each carrying malicious Microsoft Excel attachments. When victims opened those files, they were prompted to take actions that secretly downloaded the malware onto their devices.
The indictment remains sealed as of Wednesday, and the DOJ has not named the freelance company that was hit.
How the malware worked
TVRAT is a nasty piece of code that exploits a vulnerability in TeamViewer, a popular remote access tool. Once installed, it gives attackers full control over a victim’s device.
Aktulaev also used a second strain of malware called DarkVNC, which did the same thing but targeted a bug in VNC Viewer, another remote administration tool.
With that level of access, Aktulaev allegedly stole data and committed fraud. He kept command-and-control domains active after the initial infection, allowing him to return to compromised devices whenever he wanted.
Victims concentrated in California
About half of the victims were based in the U.S., with a heavy concentration in California. Prosecutors say Aktulaev maintained a document containing stolen e-commerce login credentials and personal information for hundreds of victims.
That document alone paints a picture of a long-running operation — not a one-off hack. The scale of it, 80,000 infected freelancers, makes it one of the more significant malware campaigns aimed at remote workers in recent memory.
Charges and potential sentence
Aktulaev faces multiple charges, including:
- Conspiracy
- Aggravated identity theft
- Transmission of a program, information, code, and command to cause damage to a protected computer
If convicted on all counts, the maximum sentence is 20 years in federal prison.
He is currently in federal custody, with his next hearing scheduled for October 5.
Why this matters for freelancers
This case is a stark reminder that freelancers are prime targets for cybercriminals. They often work from personal devices, handle sensitive client data, and communicate through platforms that may not have enterprise-grade security.
The attack vector here — malicious Excel attachments sent through a legitimate messaging system — is still one of the most common ways malware spreads. A 2016 campaign like this one would have been cutting-edge then, but the techniques remain relevant today.
For anyone working remotely, the lesson is simple: be wary of unexpected attachments, even from people you think you know. And if a file asks you to enable macros or take other unusual steps, stop and think before clicking.
This case also highlights how international cybercrime prosecutions work. Aktulaev was arrested in Cyprus, extradited to the U.S., and is now facing justice in San Francisco. It’s a slow process, but it shows that law enforcement agencies are willing to chase suspects across borders.
The freelance platform targeted here hasn’t been named, but the impact on its users was clearly massive. For those 80,000 victims, the malware may have compromised everything from bank accounts to client contracts.
As the case moves forward, more details are likely to emerge. For now, Aktulaev sits in federal custody, awaiting his next court date. The outcome could set a precedent for how similar cross-border cybercrime cases are handled in the future.