Russian national Searzhudin Tamirlanovich Aktulaev faces federal charges in San Francisco for allegedly using 255 fake freelance accounts to infect 80,000 users with malware between 2016 and 2017.
Key Points
- Aktulaev was extradited from Cyprus to the U.S. in August 2024 to face charges including wire fraud, computer fraud, and aggravated identity theft.
- The scheme utilized malicious Excel attachments containing macros to install TVRAT and DarkVNC malware on victims' computers.
- The malware allowed attackers to gain remote control of infected systems, enabling the theft of e-commerce credentials and personal information.
- Approximately 80,000 users were targeted, with roughly half of the victims located within the United States.
- The operation relied on DLL hijacking and hidden virtual network computing to maintain stealthy access to compromised machines.