type: incident ยท created: 2026-09-03 ยท updated: 2026-09-03 ยท tags: ["incident", "malware", "teamtspy", "teamspy", "takedown", "incident-response"] ยท confidence: high ยท severity: high ยท affected_sectors: ["Freelancing", "Individuals", "Government"] ยท au_impact: false
US Charges Russian National for Malware Campaign That Infected 80,000 Freelancers
Summary
Searzhudin Tamirlanovich Aktulaev appeared in a San Francisco federal court after a May 2025 arrest in Cyprus and extradition to the US, facing conspiracy, aggravated identity theft and computer-damage charges carrying a maximum 20-year sentence. Prosecutors allege that between June 2016 and November 2017 he used 255 fake accounts on a freelance-employment platform's messaging system to distribute TVRAT (a.k.a. TVSpy/TeamSpy) via malicious Excel attachments, exploiting a TeamViewer flaw for remote takeover alongside a VNC-exploiting DarkVNC strain. About 80,000 users were infected โ roughly half in the US, mostly in California โ and the operator harvested e-commerce credentials and personal data for fraud.