US Indicts Russian National for Phishing Campaign Targeting Freelancers
TVRAT and DarkVNC malware used to compromise approximately 80,000 systems

Key Takeaways
- US Department of Justice unsealed an indictment against a Russian national for a phishing campaign targeting freelancers.
- The campaign distributed TVRAT and DarkVNC malware, resulting in approximately 80,000 compromised systems.
- TVRAT and DarkVNC are remote access trojans providing unauthorized access and data exfiltration capabilities.
- Phishing emails were the primary delivery mechanism for the malware.
- The case highlights the risk to freelancers and remote workers from socially engineered malware campaigns.
Quick answers
- What happened?
- A California federal grand jury has unsealed an indictment against a Russian national accused of conducting a phishing campaign that infected freelancers with TVRAT and DarkVNC malware. The operation allegedly compromised approximately 80,000 systems, enabling unauthorized access and data theft.
- What should defenders do?
- Organizations and individuals should exercise caution with unsolicited emails and links. Implementing email filtering, user security awareness training, and endpoint detection and response (EDR) solutions can help identify and block malware deliveries. Keeping systems patched and using strong, unique passwords are recommended security practices. If infection is suspected, systems should be isolated and scanned with updated security software.
According to court documents unsealed by the US Department of Justice, a California federal grand jury has indicted a Russian national for his role in a phishing campaign targeting freelancers. The campaign distributed TVRAT and DarkVNC malware, which are known remote access trojans (RATs) capable of providing threat actors with unauthorized access to infected systems. The indictment alleges that the actor used deceptive phishing emails to deliver the malware, resulting in the compromise of approximately 80,000 systems. The US government states the operations allowed the actor to gain persistent access to victim machines, exfiltrate data, and potentially facilitate further criminal activity. The defendant's identity and specific sentencing details remain subject to ongoing legal proceedings. The case underscores the continued threat posed by phishing-delivered RATs to remote workers and freelancers across various industries.
Security Details
The indictment describes a phishing campaign distributing TVRAT and DarkVNC. TVRAT is a remote access trojan known for providing threat actors with unauthorized access and control over infected systems. DarkVNC is similarly classified as a remote access trojan enabling remote control and data exfiltration. The specific infection vectors, command-and-control infrastructure, and full scope of data exfiltrated are details contained within the unsealed court documents and have not been independently verified outside the reporting by BleepingComputer.
Mitigation
Organizations and individuals should exercise caution with unsolicited emails and links. Implementing email filtering, user security awareness training, and endpoint detection and response (EDR) solutions can help identify and block malware deliveries. Keeping systems patched and using strong, unique passwords are recommended security practices. If infection is suspected, systems should be isolated and scanned with updated security software.
Sources
BleepingComputer
US charges Russian for infecting 80,000 freelancers with malware
Sep 2, 2026 · 09:06
Original link
Related Security News

Former US Air Force Members Sentenced to Prison for Business Email Compromise Scams
Two former members of the United States Air Force were sentenced to a combined 189 months in federal prison for their roles in a multi-year series of business email compromise (BEC) scams and phishing campaigns. The sentencing, reported by BleepingComputer in September 2026, concluded a federal case targeting individuals who abused their military backgrounds to conduct financially motivated email fraud. The attacks spanned multiple years prior to sentencing, though specific victim counts and total financial losses were not detailed in the reporting. The case underscores the legal consequences of using military credentials and training for cyber-enabled fraud.




