Russian hacker faces 20 years for massive PC data theft


Featured image Russian hacker faces 20 years for massive PC data theft

In a sprawling digital operation that touched over eighty thousand computers, a federal grand jury in California has indicted a Russian citizen for orchestrating a massive phishing campaign that stole sensitive data between 2016 and 2017. The scheme leveraged sophisticated remote-control malware to systematically breach the security of freelance employment technology platforms.

The culprit, Searzhudin Tamirlanovich Aktulaev, is facing serious federal charges, including Conspiracy, transmission of malicious code, and aggravated identity theft. The indictment details how Aktulaev conspired to exploit an online message platform to distribute malware to approximately 80,000 freelancers.

The mechanism of the attack was insidious and highly technical. Aktulaev utilized remote-control malware, specifically TVRAT (TeamViewer Remote Access Trojan) and DarkVNC, to gain remote access and steal data from the victims’ systems. By exploiting popular remote administration tools, the malware allowed the attacker to infiltrate and exfiltrate information from the infected machines.

The operation involved sending malicious Microsoft Excel attachments disguised as legitimate messages. When users opened these files, they were prompted to run a macro, which in turn downloaded the final stage of the malware. This process mirrors other widespread cyber incidents, demonstrating a calculated strategy to infect a vast network of users.

Once the data was secured, the malware communicated with a command-and-control server hosted within the United States. This server, funded using virtual currency, acted as the hub from which Aktulaev and his co-conspirators extracted the stolen information, including valuable personally identifiable information (PII) and e-commerce login credentials, from thousands of victims.

The scope of the theft was staggering. A database found on the command-and-control domain revealed thousands of victims, with roughly half of those affected residing in the United States, many of whom were residents of the Northern District of California. This breach exposed highly sensitive personal and financial details.

The legal repercussions for this cybercriminal are severe. If convicted, Aktulaev could face up to 20 years in prison and a substantial fine, potentially amounting to $250,000 or twice the total illicit gains for the conspiracy alone. The charges carry significant weight, underscoring the gravity of exploiting digital vulnerabilities for criminal enterprise.

Meanwhile, federal authorities continue to investigate related cybercrime, including other incidents where massive amounts of sensitive data, such as driver’s licenses, were leaked on Russian cybercrime forums, highlighting the ongoing threat posed by cross-border cyber operations.

You may also like: