Ryuk Ransomware Member Sentenced to 24 Months in Prison

▼ Summary
– Karen Serobovich Vardanyan was sentenced to 24 months in prison for hacking U.S. companies using Ryuk ransomware between 2019 and 2020.
– Vardanyan, who specialized in gaining initial network access, pleaded guilty after being extradited from Ukraine following his arrest in April 2025.
– The cybercriminals targeted multiple organizations including a Michigan company, a Texas school, and an Oregon technology firm, collecting over $15 million in ransoms.
– Ryuk operated as a ransomware-as-a-service model that peaked during the pandemic before shutting down in mid-2020.
– After Ryuk’s dissolution, the Wizard Spider gang switched to Conti ransomware until it disbanded in 2022 due to a data leak.
Karen Serobovich Vardanyan, a 35-year-old national of Armenia, has been sentenced to 24 months in prison followed by three years of supervised release. The penalty stems from his role as an initial access broker for the notorious Ryuk ransomware group, which targeted United States corporations by encrypting their critical data and demanding payment. Vardanyan, who operated under the online aliases “Maneeken” and “Karl Lagerfeld,” pleaded guilty in July after being extradited from Kyiv, Ukraine, where he had been arrested in April 2025.
Court records indicate that between March 2019 and June 2020, Vardanyan facilitated unauthorized entry into the networks of several U. S. entities. In one significant incident, he and his accomplices breached a Michigan-based firm, resulting in a ransom payment of 200 BTC, valued at more than $1.1 million at the time. Prosecutors also identified victims including a school district in Texas and a technology firm located in Wilsonville, Oregon. The scale of the financial impact was substantial. As stated by the U. S. Department of Justice in July:
“Vardanyan and his co-conspirators illegally accessed computer networks of victim companies and deployed ransomware on hundreds of compromised servers and workstations.”
The department further noted the immense value extracted from these operations:
“Vardanyan and his co-conspirators are alleged to have received approximately 1,610 bitcoins in ransom payments from the victim companies, which was valued at over $15 million at the time of payment.”
The Rise and Fall of Ryuk
Ryuk operated as a ransomware-as-a-service (RaaS) platform from August 2018 until its dissolution in mid-2020. It gained infamy for launching large-scale attacks against the healthcare sector during the COVID-19 pandemic. At the height of its activity, the group compromised roughly 20 victims weekly, accumulating over $150 million in ransoms. The operation relied heavily on specialized actors like Vardanyan to gain initial footholds in corporate environments before other members deployed the encryption tools.
After the Ryuk infrastructure was dismantled in 2020, the underlying criminal organization, known as Wizard Spider, transitioned to developing and distributing Conti ransomware. This new iteration quickly established itself as one of the most active and damaging hacker groups in existence. However, Conti’s reign ended abruptly in May 2022 when its internal communication logs and source code were leaked publicly. This breach forced the group to disband, with various splinter cells either joining existing ransomware syndicates or initiating independent criminal enterprises.
(Source: BleepingComputer)