Ryuk ransomware member sentenced to 24 months in prison

An Armenian man was sentenced to 24 months in prison and 3 years of supervised release for hacking U.S. companies and encrypting their systems in Ryuk ransomware attacks.
35-year-old Karen Serobovich Vardanyan (also known online as "Maneeken" or "Karl Lagerfeld"), who specialized in gaining initial access to corporate networks, pleaded guilty in July after being extradited from Kyiv, Ukraine, following his April 2025 arrest.
According to court documents, Vardanyan hacked into the networks of multiple U.S. organizations in Ryuk ransomware attacks between March 2019 and approximately June 2020.
In one of these attacks, Vardanyan and his accomplices breached a Michigan company that paid 200 BTC (worth over $1.1 million at the time). Prosecutors also said the cybercriminals breached a school in Texas and a technology company in Wilsonville, Oregon.
"Vardanyan and his co-conspirators illegally accessed computer networks of victim companies and deployed ransomware on hundreds of compromised servers and workstations," the U.S. Department of Justice said in July.
"Vardanyan and his co-conspirators are alleged to have received approximately 1,610 bitcoins in ransom payments from the victim companies, which was valued at over $15 million at the time of payment."
Ryuk was a ransomware-as-a-service (RaaS) operation active between August 2018 and mid-2020 that became notorious after launching a massive wave of attacks targeting the healthcare sector during the COVID-19 pandemic.
At its peak, the Ryuk ransomware group hacked around 20 victims every week, collecting more than $150 million in ransoms.
Following Ryuk's shutdown in 2020, the Wizard Spider cybercrime gang behind it switched to Conti ransomware, which quickly became one of the most prolific hacker groups.
However, Conti also disbanded in 2022 after its internal chats and source code were leaked in May 2022, and it splintered into multiple smaller units that infiltrated existing ransomware gangs or launched new operations.
References in this story
- Ryuk ransomware member pleads guilty in the US, faces 15 years in prison www.bleepingcomputer.com A 34-year-old Armenian man has pleaded guilty to hacking U.S. companies and deploying the infamous Ryuk ransomware to encrypt their systems.
- Ryuk ransomware’s initial access expert extradited to the U.S. www.bleepingcomputer.com A member of the notorious Ryuk ransomware operation who specialized in gaining initial access to corporate networks has been extradited to the United States.
- www.justice.gov
- Latest Ryuk news www.bleepingcomputer.com The latest news about Ryuk
- Ryuk ransomware is the top threat for the healthcare sector www.bleepingcomputer.com Healthcare organizations continue to be a prime target for cyberattacks of all kinds, with ransomware incidents, Ryuk in particular, being more prevalent.
- Hacking group is targeting US hospitals with Ryuk ransomware www.bleepingcomputer.com In a joint statement, the U.S. government is warning the healthcare industry that a hacking group is actively targeting hospitals and healthcare providers in Ryuk ransomware attacks.
- Ransomware threat surge, Ryuk attacks about 20 orgs per week www.bleepingcomputer.com Malware researchers monitoring ransomware threats noticed a sharp increase in these attacks over the past months compared to the first six months of 2020.
- Crime Laundering Primer: Inside Ryuk Crime (Crypto) Ledger & Risky Asian Crypto Traders web.archive.org By Vitali Kremez and Brian Carter We are releasing the report today with the redacted version in research collaboration with the cybersecurity firm HYAS. Inside a mature, prolific, targeted cybercrime operation. Much…
- Conti ransomware shows signs of being Ryuk's successor www.bleepingcomputer.com The Conti Ransomware is an upcoming threat targeting corporate networks with new features that allow it to perform quicker and more targeted attacks. There are also indications that this ransomware shares the same…
- Ryuk successor Conti Ransomware releases data leak site www.bleepingcomputer.com Conti ransomware, the successor of the notorious Ryuk, has released a data leak site as part of their extortion strategy to force victims into paying a ransom.
- Conti ransomware shuts down operation, rebrands into smaller units www.bleepingcomputer.com The notorious Conti ransomware gang has officially shut down their operation, with infrastructure taken offline and team leaders told that the brand is no more.



