Ryuk ransomware member sentenced to 24 months in prison
Ryuk ransomware member receives 24-month prison sentence for attacks causing over $15 million in ransom payments.
Karen Serobovich Vardanyan, a 35-year-old Armenian man, has been sentenced to 24 months in prison for his role in Ryuk ransomware attacks against U.S. companies between 2019 and 2020. Vardanyan, who specialized in initial access, pleaded guilty after being extradited from Ukraine. The Ryuk operation, attributed to the Wizard Spider cybercrime gang, was responsible for over $15 million in ransom payments before the group transitioned to the Conti ransomware-as-a-service platform.
- Ryuk ransomware member Karen Vardanyan sentenced to 24 months in prison for attacks on U.S. companies.
- Vardanyan specialized in gaining initial access and was part of an operation that received over $15 million in ransoms.
- The Ryuk group, linked to Wizard Spider, was active from 2018 to 2020 before transitioning to Conti ransomware.
- Sentencing follows Vardanyan's extradition from Ukraine after his arrest in April 2025.
Full article350 words · extracted from bleepingcomputer.com · click to collapse

An Armenian man was sentenced to 24 months in prison and 3 years of supervised release for hacking U.S. companies and encrypting their systems in Ryuk ransomware attacks.
35-year-old Karen Serobovich Vardanyan (also known online as "Maneeken" or "Karl Lagerfeld"), who specialized in gaining initial access to corporate networks, pleaded guilty in July after being extradited from Kyiv, Ukraine, following his April 2025 arrest.
According to court documents, Vardanyan hacked into the networks of multiple U.S. organizations in Ryuk ransomware attacks between March 2019 and approximately June 2020.
In one of these attacks, Vardanyan and his accomplices breached a Michigan company that paid 200 BTC (worth over $1.1 million at the time). Prosecutors also said the cybercriminals breached a school in Texas and a technology company in Wilsonville, Oregon.
"Vardanyan and his co-conspirators illegally accessed computer networks of victim companies and deployed ransomware on hundreds of compromised servers and workstations," the U.S. Department of Justice said in July.
"Vardanyan and his co-conspirators are alleged to have received approximately 1,610 bitcoins in ransom payments from the victim companies, which was valued at over $15 million at the time of payment."
Ryuk was a ransomware-as-a-service (RaaS) operation active between August 2018 and mid-2020 that became notorious after launching a massive wave of attacks targeting the healthcare sector during the COVID-19 pandemic.
At its peak, the Ryuk ransomware group hacked around 20 victims every week, collecting more than $150 million in ransoms.
Following Ryuk's shutdown in 2020, the Wizard Spider cybercrime gang behind it switched to Conti ransomware, which quickly became one of the most prolific hacker groups.
However, Conti also disbanded in 2022 after its internal chats and source code were leaked in May 2022, and it splintered into multiple smaller units that infiltrated existing ransomware gangs or launched new operations.
Build your security blueprint for AI-powered attacks
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.