Ryuk Ransomware Member Jailed for 24-Month Sentence
An Armenian national has been handed a 24-month prison term and three years of supervised release for orchestrating cyberattacks on U.S. enterprises through Ryuk ransomware operations.
Defendant’s Sentence and Background
The 35-year-old defendant, identified as Karen Serobovich Vardanyan and associated with online aliases “Maneeken” and “Karl Lagerfeld,” admitted guilt in July after being transferred from Kyiv, Ukraine, following his April 2025 arrest.
Cyberattacks and Ransom Payments
Court records reveal Vardanyan targeted multiple U.S. organizations between March 2019 and June 2020, deploying ransomware to encrypt critical systems. One incident involved a Michigan-based company that paid 200 BTC (equivalent to over $1.1 million at the time) to cybercriminals. Additional breaches affected a Texas educational institution and an Oregon-based technology firm.
Ryuk Ransomware Operations
The U.S. Department of Justice stated in July that Vardanyan and his collaborators infiltrated corporate networks, deploying ransomware across hundreds of servers and workstations. Prosecutors noted the group secured approximately 1,610 bitcoins in ransom payments, valued at over $15 million during the transactions.
Ryuk’s RaaS and Impact
Ryuk operated as a ransomware-as-a-service (RaaS) platform from August 2018 until mid-2020, gaining notoriety for extensive attacks on healthcare entities during the COVID-19 pandemic. The group reportedly compromised around 20 organizations weekly at its peak, amassing over $150 million in ransoms.
Aftermath and Transition to Conti
After its dissolution in 2020, the Ryuk operation’s infrastructure was assumed by the Wizard Spider cybercrime collective, which transitioned to Conti ransomware. Conti later fragmented in 2022 following the exposure of internal communications and source code in May 2022, leading to the formation of smaller factions that integrated into existing ransomware operations or initiated new campaigns.
