A California federal grand jury has indicted Russian national Searzhudin Tamirlanovich Aktulaev over an alleged phishing campaign that targeted freelancers, BleepingComputer reports, citing court documents and a Justice Department statement. According to the report, Aktulaev, 40, was arrested at Larnaca Airport in Cyprus in May 2025 and extradited to the United States. Court documents filed in June 2021 were unsealed this week, bringing the allegations into public view. Prosecutors allege that between June 2016 and November 2017, Aktulaev abused the online messaging system of an unnamed freelance employment technology company based in the Northern District of California. BleepingComputer reports that he used 255 fake user accounts to send Microsoft Excel attachments containing malicious macros to 80,000 freelancers. Those attachments allegedly downloaded malware onto targets’ systems. The reported tools were TVRAT, also known as TeamSPy or TVSPY, and DarkVNC. BleepingComputer says the malware gave attackers remote control of infected machines through TeamViewer and VNC Viewer remote administration tools, respectively. The Justice Department said, according to BleepingComputer, that both malware families sent stolen data from victim computers to command-and-control servers, where the data was collected and used by Aktulaev and co-conspirators for fraud or other criminal activity. The report says investigators also found stolen e-commerce login credentials and personally identifiable information. The infrastructure detail matters. BleepingComputer reports that the command-and-control domains were paid for using virtual currency, and that thousands of machines infected with TVRAT were calling back to a command-and-control domain hosted in the United States. Investigators found that half of infected victims were in the United States, many in the Northern District of California, according to the report. Aktulaev is now in federal custody and is scheduled to appear before U.S. District Judge Donato on October 5. BleepingComputer also notes that the Justice Department separately announced Monday that it is working with international law enforcement and private partners to dismantle infrastructure tied to the Russian-linked Sality botnet. The provided report does not state that the Sality action is part of the Aktulaev case. Who benefits: Security teams at freelance platforms and marketplaces gain a concrete example for tightening account abuse controls, attachment handling, and macro-file defenses. Incident responders also get named malware families and remote-control methods to track in historical investigations. Who's exposed: Freelancers and marketplace users remain exposed when platform messaging creates implicit trust around attachments from supposed clients or workers. Companies relying on distributed freelance labor can also inherit risk if compromised contractor machines hold credentials or business data.