2 SEP 2026 — US prosecutors have charged Searzhudin Tamirlanovich Aktulaev, 40, with infecting about 80,000 freelancers using 255 fake accounts on a freelance platform to send Excel attachments carrying TVRAT and DarkVNC. The campaign ran in 2016 and 2017. He was indicted in 2021, arrested in Cyprus in 2025, and appears in court next month.
The case
Between June 2016 and November 2017, according to the indictment, Aktulaev created 255 fake accounts on an unnamed California-based freelance employment platform and used them to distribute Microsoft Excel attachments containing malicious macros. Opening one downloaded TVRAT, also tracked as TeamSPy or TVSPY, and DarkVNC.
Both provide remote control of the machine through TeamViewer and VNC Viewer. The Department of Justice says the malware sent stolen data to a command-and-control server used to commit fraud and other crimes; e-commerce login credentials and personally identifiable information are named.
Roughly 80,000 freelancers were infected, about half in the United States and particularly in Northern California. A federal grand jury indicted him on documents filed in June 2021. He was arrested at Larnaca Airport in Cyprus in May 2025 and extradited, and is due before US District Judge Donato on 5 October. No financial impact figure appears in the available filings.
The arrest location is the whole enforcement story
An indictment against a Russian national living in Russia is a document with no immediate effect. There is no extradition treaty in force between the two countries, and none of the usual instruments reach someone who stays home.
Travel changes the equation. The arrest happened at an airport in Cyprus because an Interpol notice was waiting there, ready to be executed the moment the subject entered a jurisdiction that would act on it.
Which explains the shape of the timeline rather than excusing it. The four years between indictment and arrest were not investigation; they were waiting. What this system actually produces, then, is a permanent restriction on where someone can travel, which is a long way from a consequence faced at home.
The lure was aimed at people who cannot follow the advice
Every awareness programme tells staff not to open attachments from strangers. A freelancer's job is to open attachments from strangers.
A brief arrives as a document. A specification arrives as a spreadsheet. A prospective client who sends nothing but a message is the unusual one, and a freelancer who declines to open files loses work to one who does not. This group was chosen precisely because that standard advice is impossible for them to follow.
The 255 accounts matter for the same reason. A platform profile carries the signals people are taught to check — a completed profile, a history, a plausible request — and creating 255 of them is a few hours of work. The trust that makes a marketplace function was the currency being spent.
Eighty thousand infections, and the platform is not named
The indictment describes an unnamed California-based freelance platform, an omission that matters.
Charging documents name a victim when the victim is the injured party. Here the injured parties are the 80,000 freelancers, and the platform is the medium through which they were reached — a distinction that spares it identification but also leaves the wider question unaddressed. A campaign that ran for seventeen months on 255 accounts is a long time for the abuse detection on a marketplace to see nothing.
Nothing in the reporting says the platform failed to act, and no such claim is made here. The public record details what the defendant did and says nothing about what the marketplace did. That is the usual asymmetry in cases of this kind, and it is why platform practices rarely change as a result.
Excel macros in 2016 and what replaced them
The technique is dated, but for a specific reason. Microsoft eventually blocked macros by default in files downloaded from the internet, which removed most of the value from this exact approach.
What followed was not a return to safety. Attackers moved to container formats that carry a shortcut or script, to installers that look like the tool a client asked you to use, and most recently to instructions that ask the recipient to run a command themselves — the pattern behind the ClickFix and TerminalFix campaigns we covered this week.
Across all of them the file format changes and the recipient does not. Each generation targets the same decision by the same person, and each is defeated by the same habit, which is checking what a document is before opening it rather than after.
Why this population matters in this region
Southeast Asia supplies a large share of the world's freelance labour on exactly these platforms — designers, developers, writers and analysts in Manila, Jakarta, Ho Chi Minh City and Kuala Lumpur working for clients they will never meet.
That workforce carries the exposure without any of the infrastructure an employee would have behind them, from device management through to somebody to call when something goes wrong. The machine that opens the client's spreadsheet is usually the same one holding the bank details, the platform credentials and every past client's files.
Two habits carry most of the protection here and neither costs anything. Open unfamiliar documents in the browser preview or a cloud viewer rather than the desktop application, since a macro cannot run in a viewer that does not execute them. And keep the work separate from the money, so that a compromised machine is a bad week rather than an emptied account. We reported on the TerminalFix campaign that persuades people to paste a command into their own terminal, which is the current version of the same trick against the same target.