Ryuk ransomware member sentenced to 24 months in prison

by · BleepingComputer

An Armenian man was sentenced to 24 months in prison and 3 years of supervised release for hacking U.S. companies and encrypting their systems in Ryuk ransomware attacks.

35-year-old Karen Serobovich Vardanyan (also known online as "Maneeken" or "Karl Lagerfeld"), who specialized in gaining initial access to corporate networks, pleaded guilty in July after being extradited from Kyiv, Ukraine, following his April 2025 arrest.

According to court documents, Vardanyan hacked into the networks of multiple U.S. organizations in Ryuk ransomware attacks between March 2019 and approximately June 2020.

In one of these attacks, Vardanyan and his accomplices breached a Michigan company that paid 200 BTC (worth over $1.1 million at the time). Prosecutors also said the cybercriminals breached a school in Texas and a technology company in Wilsonville, Oregon.

"Vardanyan and his co-conspirators illegally accessed computer networks of victim companies and deployed ransomware on hundreds of compromised servers and workstations," the U.S. Department of Justice said in July.

"Vardanyan and his co-conspirators are alleged to have received approximately 1,610 bitcoins in ransom payments from the victim companies, which was valued at over $15 million at the time of payment."

Ryuk was a ransomware-as-a-service (RaaS) operation active between August 2018 and mid-2020 that became notorious after launching a massive wave of attacks targeting the healthcare sector during the COVID-19 pandemic.

At its peak, the Ryuk ransomware group hacked around 20 victims every week, collecting more than $150 million in ransoms.

Following Ryuk's shutdown in 2020, the Wizard Spider cybercrime gang behind it switched to Conti ransomware, which quickly became one of the most prolific hacker groups.

However, Conti also disbanded in 2022 after its internal chats and source code were leaked in May 2022, and it splintered into multiple smaller units that infiltrated existing ransomware gangs or launched new operations.

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat