Search TorWire

Find cybersecurity guides and research articles

Home > News > Cybersecurity > Russian National Faces US Charges Over Malware Sent through 255 Fake Accounts

Russian National Faces US Charges Over Malware Sent through 255 Fake Accounts

By: Morgan Cipher Senior Privacy Journalist

Last updated: September 2, 2026

Human Written
Russian National Faces US Charges Over Malware Sent through 255 Fake Accounts
  • Federal authorities extradited 40-year-old Russian national Searzhudin Tamirlanovich Aktulaev from Cyprus to face serious computer fraud and identity theft charges in San Francisco.

  • The suspect reportedly introduced 255 counterfeit accounts on a much-utilized freelancing website to deliver malware-infested Excel files to around 80,000 potential victims.

  • The operation used VBA macros to infect the computers of victims with TVRAT and DarkVNC malware, employing DLL search order hijacking.

Federal prosecutors in California have recently unsealed criminal charges against a suspected Russian cybercriminal extradited from Cyprus. The individual allegedly ran a massive email scam, and he subsequently infected tens of thousands of business computers worldwide.

The defendant utilized a large number of fake accounts on the biggest job placement website to send malware files. As a result, the malicious documents equipped the hacker with the tool for spying and acquiring confidential information from its victims.

Extradition and Initial Court Appearance in San Francisco

Authorities brought forty-year-old Russian citizen Searzhudin Tamirlanovich Aktulaev into federal custody after completing his extradition process on August 28. Officials originally arrested the suspect in Cyprus during May 2025 following a long-standing U.S. law enforcement request.

Aktulaev later appeared in a San Francisco courtroom, where a federal judge ordered him remanded into custody. The court unsealed an indictment originally filed in June, five years ago that names the defendant in several serious conspiracy counts.

The underlying indictment focuses on an extensive cyberattack wave conducted from June 2016 through November the following year. Prosecutors allege that Aktulaev created roughly 255 fake user profiles on a major freelance job site.

By employing these fabricated profiles, the criminal was able to transmit harmful Microsoft Excel files to almost 80,000 users of the platform. In addition, the scheme threatened systems all over the world; around 50 percent of the known victims were located within the United States.

The fake user profiles made it easier for the perpetrators to contact victims without setting off security alerts. By presenting their message as inquiries in relation to real job projects, the criminals lured unsuspecting victims into downloading files.

Consequently, the scam spread rapidly across the professional network, affecting numerous remote workers and business entities.

Exploit Mechanics and Dual Malware Payloads

When targeted users opened the malicious spreadsheet files, hidden prompts asked them to enable embedded macro code. Once activated, the macro scripts immediately downloaded secondary malware payloads from external servers.

The campaign deployed two main tools to compromise endpoint security: a modified remote access trojan named TVRAT and a hidden virtual network computing tool known as DarkVNC. Consequently, both malicious utilities granted the attackers full remote control over affected desktop environments.

The TVRAT variant relies on a clever execution method called DLL search order hijacking. The macro dropped a legitimate, digitally signed TeamViewer installer alongside a malicious file named msimg32.dll.

Because the main application executable was officially signed, standard security checks showed no suspicious activity. However, the fake dynamic-link library intercepted dozens of system operations to hide all remote window controls from the victim.

Alternatively, the DarkVNC payload created a completely hidden secondary desktop on the compromised host machine. This concealed interface allowed the attackers to navigate local files and execute commands without alerting the active user.

Fortunately, tech giant Microsoft blocked internet-sourced VBA macros by default in Office, effectively shutting down this primary infection vector. Modern security tools now inspect incoming Office documents more aggressively to prevent similar macro execution attempts.

The malicious software regularly transmitted harvested victim data back to a central command and control server infrastructure. Analysts inspecting the infrastructure discovered a centralized database containing compromised e-commerce credentials alongside extensive personally identifiable information.

Additionally, thousands of infected client machines reported back to server domains hosted inside the United States. The orchestrators made use of the misappropriated personal data to engage in hacking attempts and unauthorized access to accounts.

Among the misappropriated details were important login credentials, payment information, and private files of various clients. The hackers ensured comprehensive system access and stole confidential saved cookies and passwords without the knowledge of users. The workers operated continuously in the background, exfiltrating fresh logs whenever an infected computer connected to the internet.

The federal indictment against Aktulaev includes a number of serious charges like conspiracy to commit wire fraud and the crime of computer fraud. There are also charges concerning the transmission of malware, illegal gain of access, and aggravated identity theft.

The person may face a punishment of twenty years in jail on the main wire fraud accusation if proved guilty. Meanwhile, Russian diplomatic representatives stated that Aktulaev previously denied all wrongdoing before his extradition.

The U.S. government is also targeting Russian cybercriminals through the State Department’s Rewards for Justice program, which offers up to $10 million for information on groups UNC5792 and UNC4221. The groups targeted officials, military leaders, journalists, and allies through phishing attacks on Signal and WhatsApp, stealing Signal Backup Recovery Keys to access past chats.

Persistent Targeting of Online Job Platforms

This case demonstrates an ongoing trend of how cyber crooks are misusing employment sites to carry out criminal schemes. Criminal crews create fake job offers or freelance tasks that entice unsuspecting applicants to open dangerous files.

For instance, experts in cybersecurity reported their findings on the use of fraudulent recruitment messages by state-sponsored hackers who targeted software developers with the help of backdoor programs. Similarly, other advanced hacking units contacted job seekers through site chat functions to push trojanized software utilities.

Organized threat groups favor recruitment channels because job applicants naturally expect to receive external files, such as project briefs and resumes. Hence, individuals must be very careful while opening files received through freelance websites and professional networks.

Companies should use updated endpoint security tools, establish strict procedures for effective administration of macro setups, and educate the personnel about social engineering schemes. Verifying the file extension as well as checking unsolicited attachments is obligatory for preventing remote access Trojans.

Site administrators must also implement stricter identity verification protocols for employer accounts registered on recruitment platforms. Also, verifying client profiles prior to allowing bulk messaging can prevent many instances of the dissemination of malicious attachments.

Tackling social engineering campaigns of multi-stage vectors requires active cooperation between the job portals, cybersecurity companies, and international law enforcement agencies.

Share this article

You might also like

13 Malicious Packagist Packages Target iPhones With Spyware and Crypto Stealer

13 Malicious Packagist Packages Target iPhones with Spyware and Crypto Stealer

Security researchers discovered 13 trojanized Composer theme packages on Packagist that target movie and comic streaming websites to inject harmful…

September 2, 2026
Rhysida Claims Berlin Government Data Theft as City Refuses Ransom Demand

Berlin Refuses Ransom After Government Cyberattack as Rhysida Claims 5.79TB Data Theft

A ransomware gang called Rhysida attacked Berlin’s state government network and stole internal files. The group claims it took 5.79…

September 1, 2026
French Government Housing Platform Hit by Data Breach Claim Affecting 48 Million People

French Government Housing Platform Hit by Data Breach Claim Affecting 48 Million People

A hacking group called ZeroBytes claims it broke into Zero Vacant Housing, a French government housing platform. The gang says…

September 1, 2026

About the Author

Morgan Cipher

Morgan Cipher

Senior Privacy Journalist

Morgan combines a journalist’s curiosity with a security specialist’s precision. His reporting on data breaches, privacy laws, and encryption tech has been featured in several tech publications. At TorWire, he focuses on real-world threats and how to counter them, always with an eye on what’s next in digital privacy.

Comments (0)

No comments.