Bay Area/ San Francisco/ Crime & Emergencies

San Francisco Prosecutors Charge Russian Man in 80,000-Victim Malware Scheme

AI Assisted Icon
Published on September 02, 2026
San Francisco Prosecutors Charge Russian Man in 80,000-Victim Malware SchemeSource: Google Street View

A federal grand jury has indicted a 40-year-old Russian national accused of exploiting the messaging system of a well-known freelance employment platform based in the Northern District of California to spread malware to roughly 80,000 users worldwide. Searzhudin Tamirlanovich Aktulaev was arrested in Cyprus in May 2025, extradited to the United States, and made his initial appearance in federal court in San Francisco this week, where he was remanded to federal custody.

According to the indictment, which was filed June 1, 2021 and unsealed Monday, Aktulaev and his co-conspirators used approximately 255 fake user accounts to send messages containing malicious Microsoft Excel attachments between June 2016 and November 2017. Opening the attachments prompted victims to run a macro that silently downloaded malware, a tactic consistent with how cybercriminals have long targeted freelance and remote-employment platforms by disguising infected files as job applications or project specifications, according to Trend Micro. The scheme allegedly reached approximately half its victims in the United States, with many located in the Northern District of California, according to the U.S. Department of Justice, whose announcement forms the basis of this report and can be read in full via U.S. Attorney Craig Missakian.

Two Malware Strains Tied to Legitimate Remote-Access Tools

The indictment describes Aktulaev's alleged use of two distinct malware variants. The first, known as TVRAT or TVSPY and also referred to as TeamSpy, is a modified version of the legitimate remote-desktop program TeamViewer, first documented by security researchers with CrySyS Lab and Kaspersky in 2013 as a tool built for covert surveillance and data theft. The second, called DarkVNC, functions similarly but exploits the VNC Viewer remote administration tool instead of TeamViewer; cybersecurity firm eSentire has traced DarkVNC's origins to an underground forum called Exploit, where it was first advertised in November 2016.

Both malware types allegedly sent stolen data from infected victim computers to command-and-control servers, which prosecutors say were paid for using virtual currency. The indictment states that thousands of computers infected with TVRAT were calling back to a command-and-control domain hosted in the United States, and that a database found on that domain revealed thousands of victims. A shared document tied to an email account used in the alleged criminal activity reportedly contained e-commerce login credentials and personally identifiable information for hundreds of victims, which the indictment alleges was used to commit fraud or other criminal activity.

Extradition From Cyprus Followed Years-Long Investigation

Aktulaev's case adds to a growing list of Russian nationals apprehended after traveling to Cyprus, a jurisdiction that has become a key arrest point for U.S. authorities because Russia's constitution bars extraditing its own citizens. The District Court of Larnaca formally granted the U.S. extradition request in May 2026 under the U.S.-Cyprus extradition treaty's dual criminality framework, which requires that the charged conduct be a felony under both nations' laws, as reported by UA News. The Justice Department's Office of International Affairs secured Aktulaev's extradition last Friday. Federal prosecutors previously used the same pathway in August 2024 to extradite dual Russian-German national Arthur Petrov from Cyprus on wire fraud, smuggling, and export control charges, according to the U.S. Department of Justice.

The investigation into Aktulaev was carried out by the Federal Bureau of Investigation, and the case is being prosecuted by the National Security, Cyber, and Special Prosecutions Section. U.S. Attorney Craig H. Missakian and FBI Special Agent in Charge Scott R. Scheble announced the indictment. Missakian, who was appointed U.S. Attorney for the Northern District of California in May 2025, has outlined prosecutorial priorities centered on transnational cybercrime syndicates, investor fraud, and intellectual property theft, according to Local News Matters.

Steep Prison Exposure If Convicted

Aktulaev faces a maximum of 20 years in prison and a $250,000 fine, or twice the gross gain, for conspiracy to commit wire fraud. He also faces up to 10 years for transmitting a program to damage 10 or more protected computers in a one-year period, and up to five years for related computer fraud and unauthorized-access offenses. Separately, each aggravated identity theft count carries a mandatory two years in prison that must run consecutively to any other sentence imposed — a penalty federal judges have no discretion to reduce or run concurrently, according to Cron Israels & Stark. Any eventual sentence would be determined by the court after weighing the U.S. Sentencing Guidelines and the federal sentencing statute, 18 U.S.C. § 3553.

The indictment merely alleges that crimes were committed, and Aktulaev, like all defendants, is presumed innocent until proven guilty beyond a reasonable doubt. He is next scheduled to appear in district court on October 5, 2026 for a status conference before U.S. District Judge Donato. The case carries the docket number 21-0229 J.

Part of a Broader National Pattern

The case lands amid a sharp rise in reported cybercrime losses nationwide. The FBI's Internet Crime Complaint Center reported that total cybercrime losses surpassed $20.8 billion in 2025 across more than one million complaints, a record and a 26 percent jump over the prior year, according to SOCRadar. California has consistently led all states in total internet crime victim complaints and financial losses, a trend the FBI attributes to the concentration of technology companies and remote workers that makes Northern California a frequent target for online fraud.