Armenian Actor Sentenced to Prison for Ryuk Ransomware Attacks
Share
An Armenian national has been sentenced to 24 months in prison and three years of supervised release for his role in a series of Ryuk ransomware attacks targeting organisations in the United States.
Karen Serobovich Vardanyan, 35, specialised in gaining initial access to corporate networks. Vardanyan, who also operated under the aliases “Maneeken” and “Karl Lagerfeld”, pleaded guilty in July following his extradition from Kyiv, Ukraine, after being arrested in April 2025.
Court documents reveal that Vardanyan breached the networks of multiple US entities between March 2019 and approximately June 2020. In one instance, Vardanyan and his accomplices targeted a Michigan company that paid 200 Bitcoin (BTC) in ransom, valued at more than $1.1 million at the time.
The criminal activity also included breaches of a school in Texas and a technology firm based in Wilsonville, Oregon.
Scale of the Ryuk Criminal Operation
The United States Department of Justice stated that Vardanyan and his co-conspirators deployed ransomware on hundreds of compromised servers and workstations. The group is alleged to have received approximately 1,610 bitcoins in ransom payments, a sum valued at over $15 million at the time of the transactions.
Ryuk was a notorious ransomware-as-a-service (RaaS) operation active between August 2018 and mid-2020. The group became particularly well-known for launching massive waves of attacks against the healthcare sector during the COVID-19 pandemic. At its peak, the group was estimated to target around 20 victims every week, collecting more than $150 million in total ransoms.
Following the shutdown of Ryuk in 2020, the Wizard Spider cybercrime gang associated with the malware transitioned to Conti ransomware. Conti remained a prolific threat until its disbandment in 2022, following the leak of its internal source code and communications.




Leave a Reply