Ryuk ransomware operator sentenced to 2 years in prison
Armenian Ryuk operator Karen Vardanyan received a two-year U.S. sentence and about $1.2 million restitution.
The U.S. Justice Department said Karen Vardanyan, a 35-year-old Armenian national extradited from Ukraine, was sentenced to two years in prison after pleading guilty to computer fraud and conspiracy tied to Ryuk ransomware attacks in 2019 and 2020. The sentence includes about $1.2 million in restitution and three years of supervised release, followed by removal from the United States. Court records cite a Michigan company that paid nearly $1.2 million, an Oregon technology company, and a Texas school. Prosecutors said Vardanyan and co-conspirators received about 1,160 bitcoins, then worth more than $15 million, after deploying Ryuk on hundreds of systems.
- Vardanyan pleaded guilty in July after extradition from Ukraine.
- Sentence is two years, about $1.2 million restitution, and three years supervised release.
- Co-conspirators include two Ukrainian nationals and another Armenian national.
- Prosecutors say the group received about 1,160 bitcoin, then over $15 million.
Full article620 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The Armenian national was extradited from Ukraine to the United States last year and pleaded guilty to cybercrimes in July.
Listen to this article
0:00
Learn more.
A 35-year-old Armenian national was sentenced to two years in prison for his involvement in a series of Ryuk ransomware attacks while living in Ukraine and Russia in 2019 and 2020, the Justice Department said Tuesday.
Karen Vardanyan was extradited from Ukraine to the United States last year and pleaded guilty to computer fraud and conspiracy to commit fraud and extortion in July. Vardanyan’s sentencing, which also calls for about $1.2 million in restitution to victims, matches terms of a plea agreement he reached with prosecutors.
Vardanyan and his co-conspirators’ victims include a Michigan-based company that paid a ransom of nearly $1.2 million in January 2020, a Watsonville, Oregon-based technology company that was attacked in December 2019 and a Texas-based school breached in February 2020, according to court records.
“Like Vardanyan, many cybercriminals are not masterminds of a complex ransomware or extortion scheme but nonetheless play an integral part in the success of these crimes,” read a memo signed by U.S. attorneys in the District of Oregon.
“Unfortunately, high rewards and a relatively low risk of detection are basic features of cybercrime. The only way to affect the cost-benefit analysis of these crimes is to impose meaningful sentences on those who are caught,” the U.S. attorneys added.
Prosecutors previously accused Vardanyan and his co-conspirators — Ukrainian nationals Oleg Nikolayevich Lyulyava and Andrii Leonydovich Prykhodchenko, and Armenian national Levon Georgiyovych Avetisyan — of illegally accessing computer networks to deploy Ryuk ransomware on hundreds of compromised servers and workstations between March 2019 and September 2020.
Ryuk ransomware was prevalent in 2019 and 2020, infecting thousands of victims globally across the private sector, state and local municipalities, local school districts and critical infrastructure, including a wave of attacks on U.S. hospitals.
Victims of Ryuk ransomware attacks include Hollywood Presbyterian Medical Center, Universal Health Services, Electronic Warfare Associates, a North Carolina water utility and multiple U.S. news outlets.
Justice Department officials said Vardanyan and his co-conspirators received about 1,160 bitcoins — valued at more than $15 million at the time — in ransom payments from victim companies.
Prosecutors said they found no evidence Vardanyan was still engaged in criminal activity at the time of his arrest. Vardanyan’s incarceration will be followed by three years of supervised release, and his conviction will have immigration consequences resulting in removal from the United States after serving his sentence.
Latest Podcasts
Government
After water attacks, Capitol Hill offers its own proposal for an AI-cyber test program
Citing China, President Trump doubles down on hands-off approach to AI regulation
Dems seek top-to-bottom assessment of CISA workforce
International security agencies warn about North Korean hackers exploiting job seekers to steal crypto, data
Technology
Threats
Volexity spots another China-aligned threat group exploiting Chrome and Microsoft defects
Microsoft and partners disrupt EvilTokens, a comprehensive cybercrime service for financial fraud
Another worry for water systems: infostealer exposure
Cisco alerts customers to second actively exploited zero-day in as many days