Russian national Searzhudin Tamirlanovich Aktulaev was extradited from Cyprus to the United States to face federal charges over an alleged 2016–2017 phishing operation that compromised more than 80,000 computers. Prosecutors allege Aktulaev and co-conspirators created roughly 255 fraudulent accounts on a freelance-employment platform and sent targets malicious Excel attachments designed to persuade them to enable macros.
The macro-enabled files allegedly downloaded the TVRAT and DarkVNC remote-access trojans, allowing the operators to steal victim information and exfiltrate it through U.S.-hosted command-and-control infrastructure. The campaign affected thousands of victims, approximately half in the United States; Aktulaev faces charges including conspiracy, computer-damage offenses, and aggravated identity theft, with potential penalties of up to 20 years in prison.

See the reporting duties and controls this puts on the clock.
7 events from the most recent confirmed update back to the earliest known activity.
The federal indictment against Aktulaev was publicly released, disclosing allegations that the operation compromised more than 80,000 computers and collected stolen data through U.S.-hosted command-and-control infrastructure.
Aktulaev appeared in federal court in San Francisco and was remanded to federal custody.
Cyprus extradited Aktulaev to the United States over the federal allegations concerning the 2016–2017 malware operation.
Aktulaev was arrested in Cyprus in connection with the alleged malware campaign.
A federal grand jury in California indicted Aktulaev on allegations including conspiracy, computer-damage offenses, unauthorized access, and aggravated identity theft.
The alleged phishing and malware distribution operation ran through November 2017, targeting approximately 80,000 platform users and infecting thousands of systems.
Aktulaev and alleged co-conspirators began using roughly 255 fraudulent freelance-platform accounts to send malicious Excel attachments. Recipients who enabled macros allegedly downloaded TVRAT or DarkVNC, enabling remote access and theft of victim data.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
12 references tracked. Mallory keeps watching after this page renders.
infosec.pub
Open sourcecysecurity.news
Open sourcescworld.com
Open sourcexakep.ru
Open sourceinfosecurity-magazine.com
Open sourcetomshardware.com
Open sourcecybersecuritynews.com
Open sourcejustice.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.