MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-09-02 · via Tom's Hardware

Russian National Indicted for Phishing Scheme Affecting 80,000 PCs

Image via Tom's Hardware
Image via Tom's Hardware

Russian national Searzhudin Tamirlanovich Aktulaev has been indicted in California for a phishing campaign that compromised more than 80,000 computers from 2016 to 2017. He allegedly used TVRAT and DarkVNC remote-access malware delivered through malicious Excel files on a freelance platform. Aktulaev was extradited from Cyprus and faces up to 20 years in prison.

Expanded Detail

The phishing operation ran from June 2016 through November 2017, targeting freelancers on a well-known employment platform headquartered in Northern California. Aktulaev allegedly created roughly 255 fake user accounts to distribute malicious Excel attachments; when opened, these files prompted victims to enable macros that downloaded TVRAT and DarkVNC remote-access trojans from the internet.

Once installed, the malware granted attackers remote control over infected systems, enabling theft of login credentials and personal information. A database discovered on the command-and-control domain revealed thousands of victims, with approximately half located in the United States. The domain was paid for using virtual currency. Aktulaev was arrested in Cyprus in May 2021 and extradited in August 2026, facing charges that include conspiracy, transmission of malicious code, and aggravated identity theft.

Context

This case underscores how phishing schemes continue to exploit trust in legitimate freelance platforms, potentially affecting remote workers who depend on such services for income. If convicted, the 20-year maximum sentence could serve as a deterrent, though the scale—80,000 compromised computers—highlights how a single actor can inflict widespread harm. Victims may face long-term consequences from stolen personal data, including identity theft and financial fraud, persisting well beyond the original breach period.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at Tom's Hardware →
This summary is AI-generated and original to Mobble; the linked article is the authoritative source. Original headline: “Russian hacker faces up to 20 years in prison, following extradition and indictment over US phishing campaign that allegedly infected 80,000 PCs — hacker stole victims' data via remote access.” Browse more stories.