Extradited Access Broker Sentenced in Oregon
An Armenian national who specialized in gaining initial access to corporate networks for the Ryuk ransomware operation has been sentenced to 24 months in prison and 3 years of supervised release, the U.S. Department of Justice announced.
Karen Serobovich Vardanyan, 35 — known online as "Maneeken" and "Karl Lagerfeld" — was extradited from Kyiv, Ukraine, following his April 2025 arrest, and pleaded guilty in July. He was sentenced in federal court in the District of Oregon.
Case Details
| Field | Details |
|---|---|
| Defendant | Karen Serobovich Vardanyan, 35 (Armenia) |
| Online aliases | Maneeken, Karl Lagerfeld |
| Ransomware family | Ryuk (Wizard Spider) |
| Attack window | March 2019 – approximately June 2020 |
| Charges | Conspiracy, computer fraud, extortion |
| Sentence | 24 months prison + 3 years supervised release |
| Restitution ordered | $1,219,106.00 |
| Maximum exposure | Up to 15 years |
Scale of the Conspiracy
Vardanyan and his co-conspirators are alleged to have collected roughly 1,610 bitcoins in ransom payments across their Ryuk campaign — worth over $15 million at the time victims paid.
Named victims in the case include:
- A Michigan company that paid 200 BTC (over $1.1 million at the time) after a breach
- A school district in Texas
- A technology company in Wilsonville, Oregon
A federal grand jury in Portland returned a three-count indictment against Vardanyan on February 22, 2024. The investigation was a multi-agency effort involving the FBI, Europol, and authorities in Ukraine and France.
Context: Ryuk to Conti and Beyond
Ryuk was one of the most damaging ransomware strains of 2019-2020 before its operators, the Wizard Spider cybercrime group, shut it down and pivoted to Conti — which became one of the most prolific ransomware operations before its internal chat logs and source code leaked in May 2022. Conti's collapse splintered its operators into multiple smaller units, some of which infiltrated existing ransomware brands and others of which launched entirely new operations still active today.
Vardanyan's role — specializing in initial access rather than encryption or negotiation — reflects the division of labor common across ransomware-as-a-service and affiliate operations, where access brokers sell footholds into corporate networks to operators who deploy the actual payload.