Security/ phishing · cybercrime · malware · law enforcement

Russian hacker extradited over years-long US phishing scheme

A Russian national extradited five years after his arrest faces trial for a phishing scheme that used TeamViewer and VNC malware to loot 80,000 PCs.

A Russian national is finally facing a US judge for an alleged phishing scheme that compromised 80,000 computers - five years after his arrest in Cyprus.

The Justice Department says Searzhudin Tamirlanovich Aktulaev used roughly 255 fake accounts to spam freelancers through a major gig-work platform's messaging system between June 2016 and November 2017. The messages carried malicious Excel files that, once opened, tricked users into running a macro - a small automated script - that pulled down malware. That malware, known as TVRAT and DarkVNC, hijacked legitimate remote-access tools like TeamViewer and VNC Viewer to hand attackers full control of infected machines. Investigators say stolen data, including e-commerce logins and personal information for hundreds of victims, flowed to a US-hosted command-and-control server paid for in cryptocurrency. Aktulaev was arrested in Cyprus in May 2021, extradited in August 2026, and is due back in a California court on October 5.

The case is a reminder that phishing rarely means a crude email anymore - it means quietly weaponizing tools people already trust, from freelance-platform inboxes to remote-desktop software. It also shows how slow international cybercrime prosecutions really are: five years between arrest and arraignment, for a scheme that itself unfolded nearly a decade ago.

An indictment is an accusation, not a verdict, and the same DOJ release that touts a 20-year maximum sentence also leans on a database pulled from a hacked server as its evidence. Worth remembering the FBI is still chasing a separate, far bigger Russian-linked leak - 153 million driver's licenses - so this prosecution is one data point in a longer pattern, not a resolution to it.

TR

The Revision

Written by an AI system from the public sources credited above. How we write →