Armenian National Sentenced for Role in Ryuk Ransomware Extortion Conspiracy
Karen Vardanyan, a 35-year-old Armenian national extradited from Ukraine to face U.S. charges, has been sentenced to 24 months (two years) in federal prison for his role in the Ryuk ransomware extortion conspiracy. A judge in the U.S. District Court for the District of Oregon also ordered Vardanyan to pay $1,219,106 in restitution to victims and imposed three years of supervised release following his prison term. The sentencing, announced by the U.S. Attorney's Office for the District of Oregon, closes out a case that began with a February 22, 2024 superseding indictment and Vardanyan's extradition from Kyiv, Ukraine, in June 2025.
Vardanyan, who also went by the aliases "Maneeken" and "Karl Lagerfeld," pleaded guilty on July 8, 2026, to conspiracy and fraud in connection with computers. Prosecutors described him as a core participant in the Ryuk operation, one of the most damaging ransomware-as-a-service campaigns of the 2019–2020 period.
Case Details
| Attribute | Value |
|---|---|
| Defendant | Karen Vardanyan (aliases "Maneeken," "Karl Lagerfeld") |
| Nationality | Armenian |
| Gang | Ryuk ransomware group (active August 2018 to mid-2020) |
| Charges | Conspiracy and fraud in connection with computers |
| Sentence | 24 months (two years) federal prison; 3 years supervised release |
| Restitution | $1,219,106 to victims |
| Court / Agency | U.S. District Court for the District of Oregon; investigated by the FBI |
| Sentencing announced | September 23, 2026 |
Background
According to court documents, Vardanyan participated in the conspiracy from March 2019 to approximately June 2020, deploying Ryuk ransomware against companies, schools, and other organizations around the world. Named victims included a Wilsonville, Oregon-based technology company attacked in December 2019, a Michigan-based company that paid a ransom of nearly $1.2 million in January 2020, and a Texas-based school district breached in February 2020.
A federal grand jury in Portland returned the superseding indictment against Vardanyan in February 2024. He was arrested in Kyiv, Ukraine, in April 2025 and made his initial appearance in U.S. federal court following extradition on June 20, 2025, where a magistrate judge ordered him detained pending trial. The Justice Department's Office of International Affairs helped secure his arrest and extradition, with U.S. authorities crediting Ukrainian authorities for their cooperation. Assistant U.S. Attorney Katherine Rykken prosecuted the case.
Vardanyan is the latest of several identified Ryuk-linked defendants to face U.S. prosecution, following fellow Armenian national Levon Georgiyovych Avetisyan and Ukrainian nationals Oleg Nikolayevich Lyulyava and Andrii Leonydovich Prykhodchenko (both 53), each of whom has been arrested over the past three years. A Russian cryptocurrency exchange executive separately pleaded guilty in 2023 to laundering ransom proceeds tied to the operation.
How Ryuk Operated
Ryuk ran as a "big-game hunting" ransomware operation from August 2018 through roughly mid-2020, and prosecutors say Vardanyan specialized in gaining initial access to corporate networks — the entry point that Ryuk affiliates relied on before deploying the encryptor. Publicly reported Ryuk campaigns typically followed a consistent pattern:
- Initial access via phishing emails or commodity malware loaders (such as TrickBot, BazarLoader, or Emotet infections) that gave operators a foothold on a victim network.
- Manual reconnaissance and lateral movement, often using tools like Cobalt Strike to map the network, escalate privileges, and identify high-value systems.
- Backup and recovery sabotage, disabling or deleting backup infrastructure before detonation to maximize leverage.
- Manual deployment of the Ryuk encryptor across as many endpoints and servers as possible, followed by a ransom note demanding payment in bitcoin.
Prosecutors said Vardanyan and his co-conspirators launched more than 2,400 ransomware attacks worldwide, including against state and local municipalities, hospitals, and school districts, and collected approximately 1,610 bitcoin in ransom payments — valued at more than $15 million at the time victims paid. Ryuk became especially notorious for targeting hospitals during the COVID-19 pandemic; across its full operational run, industry researchers estimate the broader Ryuk campaign collected more than $150 million in ransoms, hitting roughly 20 victims a week at its peak. One of the highest-profile Ryuk incidents, a 2020 attack on Universal Health Services, was separately estimated to have cost the healthcare system around $67 million in losses.
Impact Assessment
| Impact Area | Description |
|---|---|
| Financial harm | Vardanyan's conspiracy window (March 2019–June 2020) is tied to roughly $15 million in ransom proceeds paid in bitcoin; the wider Ryuk campaign is estimated to have collected more than $150 million before winding down |
| Victim sectors | Confirmed victims include a technology firm in Oregon, a Michigan company, and a Texas school district; the broader Ryuk campaign repeatedly hit hospitals, schools, and municipalities during 2019 and 2020 |
| Law enforcement momentum | Vardanyan is at least the fourth identified Ryuk-linked defendant to be arrested and prosecuted, alongside Avetisyan, Lyulyava, and Prykhodchenko |
| Remaining exposure | Ryuk's core developers and other affiliates have not been publicly identified or charged, so this case should not be read as closing out the threat posed by successor operations |
Recommendations
For Network Administrators
- Enforce multi-factor authentication on all remote access, VPN, and RDP endpoints — commodity loaders like TrickBot and BazarLoader remain a common precursor to ransomware deployment.
- Patch internet-facing systems promptly and disable or tightly restrict exposed RDP.
- Segment networks so that a single compromised endpoint cannot reach backup infrastructure or domain controllers directly.
For Security Teams
- Maintain offline, immutable backups and regularly test restoration — Ryuk-style operators specifically target and disable backup systems before detonating ransomware.
- Hunt for known precursor indicators (loader malware, Cobalt Strike beacons, unusual lateral movement) rather than waiting for encryption to trigger an alert.
- Build and rehearse an incident response plan that includes law enforcement notification (FBI, CISA) alongside technical containment steps.
For Executives and Risk Owners
- Review cyber insurance coverage and ransom-payment policies before an incident occurs, not during one.
- Treat extortion demands as a business continuity and legal issue requiring coordination between IT, legal, and executive leadership.
- Recognize that prosecutions like this one typically recover only a fraction of what victims lose — prevention and resilient backups remain the most reliable defense.
Key Takeaways
- Karen Vardanyan, 35, was sentenced to two years in federal prison and ordered to pay $1,219,106 in restitution for his role in the Ryuk ransomware conspiracy.
- Vardanyan specialized in gaining initial access to corporate networks, the entry point Ryuk affiliates used before deploying ransomware.
- Prosecutors tied Vardanyan's conspiracy window to over 2,400 attacks worldwide and roughly $15 million in ransom payments; the broader Ryuk campaign is estimated to have collected more than $150 million.
- He is at least the fourth Ryuk-linked defendant identified and prosecuted by U.S. authorities, following extraditions and arrests of Armenian and Ukrainian co-conspirators.
- Ryuk's core operators and other affiliates remain unidentified or uncharged, meaning the underlying threat model — initial access brokers feeding ransomware crews — persists today.
- Organizations should prioritize MFA, backup immutability, and precursor-malware detection over relying on law enforcement outcomes to deter future attacks.