Skip to content
Computing

Russian Hacker Faces 20 Years for Phishing 80,000 PCs

A Russian hacker could spend up to two decades in prison after being extradited to the United States and indicted for a phishing operation that allegedly compromised more than 80,000 computers. A federal grand jury in California charged Searzhudin Tamirlanovich Aktulaev, accusing him of stealing...

Russian Hacker Faces 20 Years for Phishing 80,000 PCs - Russian hacker phishing
A Russian hacker could spend up to two decades in prison after being extradited to the United States and indicted for a phishing operation that allegedly compromised more than 80,000 computers. A federal grand jury in Ca

A Russian hacker could spend up to two decades in prison after being extradited to the United States and indicted for a phishing operation that allegedly compromised more than 80,000 computers. A federal grand jury in California charged Searzhudin Tamirlanovich Aktulaev, accusing him of stealing victims’ data through remote-control malware between June 2016 and November 2017.

The indictment, originally filed in June 2021 and unsealed in September 2026, was detailed in a Department of Justice press release. It lists charges including conspiracy, transmission of a program, information, code, and command to cause damage to a protected computer, and aggravated identity theft, among other offenses.

How the Phishing Attack Worked

According to prosecutors, Aktulaev conspired to abuse the online messaging platform of a well-known freelance employment technology company based in the Northern District of California. Using roughly 255 fake user accounts, he sent messages to approximately 80,000 freelancers containing malicious Microsoft Excel attachments.

Opening a file prompted the user to run a macro, which then downloaded malware from the internet. The scheme relied on two remote-access tools: TVRAT (a TeamViewer Remote Access Trojan) and DarkVNC, which exploits VNC Viewer. Both grant an attacker remote control of an infected system. The malware stole data from victims’ machines and uploaded it to a command-and-control server, where Aktulaev and his co-conspirators harvested the information to commit fraud and other crimes.

Thousands of infected computers were “calling back” to a command-and-control domain hosted in the United States and paid for with virtual currency, according to the indictment. Roughly half of the victims were in the U.S., many of them residents of the Northern District of California. Investigators say a database on the command-and-control domain revealed thousands of victims, while a shared document tied to the email account used in the scheme contained e-commerce login credentials and personally identifiable information for hundreds of people.

Extradition and Court Proceedings

Aktulaev was arrested in Cyprus in May 2021 following an FBI investigation. He was extradited to the United States in August 2026, five years after that arrest. He made his first appearance in federal court in San Francisco and was then remanded to federal custody. He is scheduled to appear in district court on October 5, 2026. The case is being prosecuted by the National Security, Cyber, and Special Prosecutions Section.

If convicted, Aktulaev faces up to 20 years in prison and a EUR 215,927 fine, or twice the total illicit gains, for the conspiracy to commit wire fraud charge alone. The remaining charges carry sentences ranging from two to twenty years, along with additional fines.

The prosecution comes as the FBI investigates a separate breach in which 153 million U.S. and Canadian driver’s licenses were leaked on a Russian cybercrime forum.

Source
Image: tomshardware.com

The US tech briefing

Smartphones, AI, computing and deals — the essential stories without the noise.

Mailing provider can be connected when your US list is ready.

Shop Amazon Tech Deals Shop Amazon Tech Deals