Freelance Malware Case Reaches U.S. Court

U.S. prosecutors have charged Searzhudin Tamirlanovich Aktulaev after his extradition from Cyprus, tying a 2016–2017 freelance-platform malware campaign to fake contractor accounts and about 80,000 infected users. The indictment was unsealed the same day he made his initial court appearance in San Francisco. The scheme used roughly 255 bogus freelancer profiles to send Excel attachments that looked like ordinary work files. When recipients opened them and enabled macros, the spreadsheet pulled down TVRAT or DarkVNC, which gave the operators remote control and let them harvest credentials and personally identifiable information from victims' mailboxes and documents. The case matters beyond the initial infections because the stolen logins and PII can keep paying off in fraud and follow-on intrusions long after the malware itself is gone. For marketplaces and contractor-heavy organizations, the abuse pattern is the point: a routine outreach channel became a bulk data-collection path.

Part of the PlainSec briefing for 2026-09-02

Every edition of this story: Freelance Malware Case Reaches U.S. Court

Sources