Russian hacker faces up to 20 years in prison, following extradition and indictment over US phishing campaign that allegedly infected 80,000 PCs — hacker stole

Russian hacker faces up to 20 years in prison, following extradition and indictment over US phishing campaign that allegedly infected 80,000 PCs — hacker stole

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works .

Aktulaev was extradited to the U.S. in August 2026, five years after his arrest in Cyprus in May 2021. He made his first appearance in federal court in San Francisco — after which he was remanded to federal custody — and is scheduled to appear in district court on October 5, 2026. The arrest was made after an FBI investigation, and the case is being prosecuted by the National Security , Cyber, and Special Prosecutions Section.

According to the indictment, Aktulaev “conspired to exploit the online message platform of a well-known freelance employment technology company, located in the Northern District of California, to spread malware to approximately 80,000 freelancers”. He sent messages containing malicious Microsoft Excel attachments, using approximately 255 fake user accounts. Once opened, the attachments prompted users to run a macro that then downloaded malware from the Internet, mirroring a hack earlier this year in which an unofficial 7-zip.com website served malware-laden downloads for over a week .

The attack used TVRAT (TeamViewer Remote Access Trojan) and DarkVNC malware, both of which grant the attacker remote control of the infected system. TVRAT exploits TeamViewer, while DarkVNC exploits VNC Viewer, popular remote administration tools. The malware stole and uploaded data from the victims' computers to a command-and-control server, from which Aktulaev and his co-conspirators extracted the stolen data to “commit fraud and other criminal activities”.

The indictment says thousands of computers infected by the TVRAT malware were “calling back” to a command-and-control domain hosted in the United States, which was paid for using virtual currency. Roughly half of the victims were in the United States, many of whom were Northern District of California residents, according to the indictment.

Windows 11 identifier used to track Scattered Spider perp after Microsoft shared info with FBI

Florida Man arrested after stealing $220,000 in crypto using malware hidden in Steam Games

Arrest and extradition of Scattered Spider hacker shines light on how Windows telemetry GDIDs can identify and track users

“A database found on the command-and-control domain revealed thousands of victims. Additionally, a shared document on the email account used in the criminal activities contained information to include e-commerce login credentials, as well as personally identifiable information (“PII”) for hundreds of victims,” the press release said.

If convicted, Aktulaev could spend up to 20 years behind bars and pay a $250,000 fine or twice the total illicit gains for the conspiracy to commit wire fraud charge alone. The other charges carry terms ranging from two to twenty years in prison, in addition to fines. Meanwhile, the FBI is currently investigating another hack in which 153 million US and Canadian drivers’ licenses were leaked on a Russian cybercrime forum .

Get Tom's Hardware's best news and in-depth reviews, straight to your inbox.

Key considerations

  • Investor positioning can change fast
  • Volatility remains possible near catalysts
  • Macro rates and liquidity can dominate flows

Reference reading

More on this site

Informational only. No financial advice. Do your own research.

Leave a Comment