U.S. Unseals Indictment Against Russian National in Freelance Platform Phishing Case

The U.S. has unsealed an indictment against Searzhudin Aktulayev. According to prosecutors, he allegedly participated in a campaign involving malicious Excel attachments sent to users of an unnamed freelance platform.

Aktulayev’s phishing campaign is the subject of a newly unsealed U.S. indictment against 40-year-old Russian national Searzhudin Tamirlanovich Aktulayev. On September 1, 2026, the U.S. Department of Justice (DOJ) announced that the man was extradited to the United States after being detained in Cyprus and appeared for the first time before a federal court in San Francisco.

The indictment was originally filed on June 1, 2021. Aktulayev was detained in Cyprus in May 2025, extradited to the U.S. on August 28, 2026, and appeared in court on August 31. He remains in federal custody. The next hearing is scheduled for October 5, 2026.

Aktulayev’s phishing campaign according to the indictment

According to the indictment, the perpetrators allegedly used approximately 255 fake accounts on an unnamed online freelance work platform from June 2016 through November 2017. Through these accounts, they allegedly sent messages with malicious Excel attachments to approximately 80,000 users.

The attachments allegedly prompted recipients to enable and run a macro. According to the DOJ, this then downloaded malware identified as TVRAT or DarkVNC. Thousands of compromised computers allegedly went on to connect to command-and-control infrastructure in the United States.

The figure of 80,000 does not represent a confirmed number of infected people or devices. It refers to the number of users who allegedly received the malicious messages. The DOJ announcement refers to thousands of infected computers, not 80,000 confirmed infections.

Old attack, new criminal case

The case concerns a historical campaign from 2016 and 2017, not a newly discovered active threat. The DOJ did not report an unpatched vulnerability, ongoing exploitation, or a new recommendation to deploy a specific security patch.

The case also highlights the risk posed by document attachments that ask users to activate macros. This can trigger the download of malicious code directly onto a device. In this matter, however, the facts, including any possible data theft and its possible use in fraud, remain allegations in the indictment.

Aktulayev has not been convicted and is presumed innocent. The DOJ also did not disclose the name of the freelance platform through which the messages were allegedly distributed, so the case cannot be linked to a specific service or its user base.

What happens next

The next procedural step is expected to be the October 5, 2026, hearing. Attention will also focus on whether the court or the DOJ makes the indictment itself and additional technical information about the campaign, such as indicators of compromise, available. It also remains an open question whether the abused platform will come forward and provide information to affected users.

Sources

Verified and updated: 09/02/2026 11:29

Sharing