> Back to All Posts

US Charges Russian Over TVRAT Malware Attack on Freelancers

TVRAT Malware

A phishing operation that ran quietly for a year and a half has finally put its alleged operator in front of a US judge. Federal prosecutors in California have indicted a Russian national over a campaign that planted TVRAT malware on the computers of 80,000 freelancers. The attack never touched a corporate network. Instead, it arrived through a messaging system that independent workers relied on to find paying jobs.

How the Phishing Campaign Reached Freelancers

Court documents name 40-year-old Searzhudin Tamirlanovich Aktulaev as the person behind the scheme. Investigators say he registered 255 fake accounts on a freelance employment platform based in Northern California. From those accounts, he sent Microsoft Excel attachments to users of the site. Every file carried a malicious macro.

Opening the spreadsheet started the infection. The macro reached out to a remote server, downloaded TVRAT malware, and installed it on the victim’s machine. Because the message came through a trusted platform, it bypassed email spam filters completely. Few freelancers would treat a file from a prospective client as a threat.

The campaign ran from June 2016 to November 2017. Over those eighteen months, 80,000 accounts received the poisoned attachments. Roughly half of the confirmed victims lived in the United States, and many of them were concentrated in the Northern District of California.

What TVRAT Malware Does Once It Lands

TVRAT malware also goes by the names TeamSPY and TVSPY. It hijacks TeamViewer, a legitimate remote administration tool that millions of people use for support and screen sharing. A second strain in the campaign, DarkVNC, did similar work through VNC Viewer. Both tools are ordinary software until an attacker turns them against their owner.

Remote control sits at the heart of the problem. Once TVRAT malware settles in, the operator can watch the screen, browse folders, move files, and drive the machine as if seated at the keyboard. There is no obvious sign of trouble. The victim keeps working while someone else watches.

The Data That Went Missing

Both malware families shipped what they collected to command-and-control servers. Prosecutors say the stolen material then fed fraud and other criminal activity. The operators paid for their command-and-control domains with virtual currency, and thousands of infected machines called back to a domain hosted inside the United States.

Investigators found that the haul included e-commerce login credentials and personally identifiable information. Those two categories fuel account takeovers, fraudulent purchases, and identity theft. So the damage did not end when the campaign stopped in 2017.

Why Freelancers Made Such Attractive Targets

Independent workers sit in an awkward security gap. They handle client data, invoices, and payment details, but they have no IT department behind them. Nobody manages their laptops or pushes security patches on a schedule. A TVRAT malware infection on a freelancer’s machine can go unnoticed for months.

The work culture adds to the exposure. Freelancers move between coffee shops, coworking spaces, and shared apartments, and they connect to whatever network is available. They also open unfamiliar attachments constantly, because reviewing a client brief is part of the job. Attackers understand that habit and build campaigns around it.

A Nine-Year Road to a Courtroom

The timeline in this case is worth pausing on. A grand jury filed the indictment in June 2021, but the documents stayed sealed until this week. Authorities arrested Aktulaev at Larnaca Airport in Cyprus in May 2025, then extradited him to the United States. He now sits in federal custody and is scheduled to appear before US District Judge Donato on October 5.

Almost nine years passed between the first infections and the defendant’s day in court. Cross-border cybercrime cases move at that pace because they depend on cooperation between multiple legal systems. Enforcement does eventually arrive, but it arrives far too late to help the people who lost credentials in 2016.

Prosecutors have been busy on the Russian cybercrime front more broadly. The Justice Department announced on Monday that it is working with international law enforcement and private partners to tear down the infrastructure behind the Russia-linked Sality botnet.

Practical Defences Against Platform-Delivered Attacks

Macro-based attacks are old, but they still work. Modern versions of Office block macros in files downloaded from the internet by default, so keeping software current matters. Never enable macros on a spreadsheet sent by someone you have not verified. If a client insists on an unusual file format, ask why.

Strong account hygiene limits the damage when something does slip through. Use a password manager, give every service its own password, and turn on two-factor authentication wherever it is offered. Then a stolen credential becomes far less useful to whoever bought it.

Network protection covers a different part of the problem. A VPN encrypts your traffic on public and shared Wi-Fi, which stops anyone on the same network from intercepting logins or session data. It will not stop a malicious macro, and no honest provider claims otherwise. However, for remote workers who connect from cafés and airports, that encryption removes one reliable avenue of attack.

Final Thoughts

Eighty thousand people opened a spreadsheet from a stranger who looked like a client. The TVRAT malware behind this campaign was not exotic, and the delivery method was not clever. Both simply landed in a place where nobody expected them.

Freelancers carry real security responsibility without corporate support, so their defences have to be personal and deliberate. Patch your software, question unexpected attachments, protect your accounts with unique passwords and 2FA, and encrypt your connection when you work outside your home network. Aktulaev may face justice this October, but the next campaign is already running somewhere.

Janet Andersen

Janet is an experienced content creator with a strong focus on cybersecurity and online privacy. With extensive experience in the field, she’s passionate about crafting in-depth reviews and guides that help readers make informed decisions about digital security tools. When she’s not managing the site, she loves staying on top of the latest trends in the digital world.