Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsTools
ProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

3030+ Articles
170+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. Ryuk Ransomware Operator Sentenced to 2 Years, Ordered to Pay $1.2 Million in Restitution
Ryuk Ransomware Operator Sentenced to 2 Years, Ordered to Pay $1.2 Million in Restitution
NEWS

Ryuk Ransomware Operator Sentenced to 2 Years, Ordered to Pay $1.2 Million in Restitution

Armenian national Karen Vardanyan was sentenced to two years in federal prison and ordered to pay $1.2 million in restitution for Ryuk ransomware attacks.

Dylan H.

News Desk

September 24, 2026
7 min read

Armenian National Sentenced for Role in Ryuk Ransomware Extortion Conspiracy

Karen Vardanyan, a 35-year-old Armenian national extradited from Ukraine to face U.S. charges, has been sentenced to 24 months (two years) in federal prison for his role in the Ryuk ransomware extortion conspiracy. A judge in the U.S. District Court for the District of Oregon also ordered Vardanyan to pay $1,219,106 in restitution to victims and imposed three years of supervised release following his prison term. The sentencing, announced by the U.S. Attorney's Office for the District of Oregon, closes out a case that began with a February 22, 2024 superseding indictment and Vardanyan's extradition from Kyiv, Ukraine, in June 2025.

Vardanyan, who also went by the aliases "Maneeken" and "Karl Lagerfeld," pleaded guilty on July 8, 2026, to conspiracy and fraud in connection with computers. Prosecutors described him as a core participant in the Ryuk operation, one of the most damaging ransomware-as-a-service campaigns of the 2019–2020 period.


Case Details

AttributeValue
DefendantKaren Vardanyan (aliases "Maneeken," "Karl Lagerfeld")
NationalityArmenian
GangRyuk ransomware group (active August 2018 to mid-2020)
ChargesConspiracy and fraud in connection with computers
Sentence24 months (two years) federal prison; 3 years supervised release
Restitution$1,219,106 to victims
Court / AgencyU.S. District Court for the District of Oregon; investigated by the FBI
Sentencing announcedSeptember 23, 2026

Background

According to court documents, Vardanyan participated in the conspiracy from March 2019 to approximately June 2020, deploying Ryuk ransomware against companies, schools, and other organizations around the world. Named victims included a Wilsonville, Oregon-based technology company attacked in December 2019, a Michigan-based company that paid a ransom of nearly $1.2 million in January 2020, and a Texas-based school district breached in February 2020.

A federal grand jury in Portland returned the superseding indictment against Vardanyan in February 2024. He was arrested in Kyiv, Ukraine, in April 2025 and made his initial appearance in U.S. federal court following extradition on June 20, 2025, where a magistrate judge ordered him detained pending trial. The Justice Department's Office of International Affairs helped secure his arrest and extradition, with U.S. authorities crediting Ukrainian authorities for their cooperation. Assistant U.S. Attorney Katherine Rykken prosecuted the case.

Vardanyan is the latest of several identified Ryuk-linked defendants to face U.S. prosecution, following fellow Armenian national Levon Georgiyovych Avetisyan and Ukrainian nationals Oleg Nikolayevich Lyulyava and Andrii Leonydovich Prykhodchenko (both 53), each of whom has been arrested over the past three years. A Russian cryptocurrency exchange executive separately pleaded guilty in 2023 to laundering ransom proceeds tied to the operation.

How Ryuk Operated

Ryuk ran as a "big-game hunting" ransomware operation from August 2018 through roughly mid-2020, and prosecutors say Vardanyan specialized in gaining initial access to corporate networks — the entry point that Ryuk affiliates relied on before deploying the encryptor. Publicly reported Ryuk campaigns typically followed a consistent pattern:

  • Initial access via phishing emails or commodity malware loaders (such as TrickBot, BazarLoader, or Emotet infections) that gave operators a foothold on a victim network.
  • Manual reconnaissance and lateral movement, often using tools like Cobalt Strike to map the network, escalate privileges, and identify high-value systems.
  • Backup and recovery sabotage, disabling or deleting backup infrastructure before detonation to maximize leverage.
  • Manual deployment of the Ryuk encryptor across as many endpoints and servers as possible, followed by a ransom note demanding payment in bitcoin.

Prosecutors said Vardanyan and his co-conspirators launched more than 2,400 ransomware attacks worldwide, including against state and local municipalities, hospitals, and school districts, and collected approximately 1,610 bitcoin in ransom payments — valued at more than $15 million at the time victims paid. Ryuk became especially notorious for targeting hospitals during the COVID-19 pandemic; across its full operational run, industry researchers estimate the broader Ryuk campaign collected more than $150 million in ransoms, hitting roughly 20 victims a week at its peak. One of the highest-profile Ryuk incidents, a 2020 attack on Universal Health Services, was separately estimated to have cost the healthcare system around $67 million in losses.


Impact Assessment

Impact AreaDescription
Financial harmVardanyan's conspiracy window (March 2019–June 2020) is tied to roughly $15 million in ransom proceeds paid in bitcoin; the wider Ryuk campaign is estimated to have collected more than $150 million before winding down
Victim sectorsConfirmed victims include a technology firm in Oregon, a Michigan company, and a Texas school district; the broader Ryuk campaign repeatedly hit hospitals, schools, and municipalities during 2019 and 2020
Law enforcement momentumVardanyan is at least the fourth identified Ryuk-linked defendant to be arrested and prosecuted, alongside Avetisyan, Lyulyava, and Prykhodchenko
Remaining exposureRyuk's core developers and other affiliates have not been publicly identified or charged, so this case should not be read as closing out the threat posed by successor operations

Recommendations

For Network Administrators

  • Enforce multi-factor authentication on all remote access, VPN, and RDP endpoints — commodity loaders like TrickBot and BazarLoader remain a common precursor to ransomware deployment.
  • Patch internet-facing systems promptly and disable or tightly restrict exposed RDP.
  • Segment networks so that a single compromised endpoint cannot reach backup infrastructure or domain controllers directly.

For Security Teams

  • Maintain offline, immutable backups and regularly test restoration — Ryuk-style operators specifically target and disable backup systems before detonating ransomware.
  • Hunt for known precursor indicators (loader malware, Cobalt Strike beacons, unusual lateral movement) rather than waiting for encryption to trigger an alert.
  • Build and rehearse an incident response plan that includes law enforcement notification (FBI, CISA) alongside technical containment steps.

For Executives and Risk Owners

  • Review cyber insurance coverage and ransom-payment policies before an incident occurs, not during one.
  • Treat extortion demands as a business continuity and legal issue requiring coordination between IT, legal, and executive leadership.
  • Recognize that prosecutions like this one typically recover only a fraction of what victims lose — prevention and resilient backups remain the most reliable defense.

Key Takeaways

  1. Karen Vardanyan, 35, was sentenced to two years in federal prison and ordered to pay $1,219,106 in restitution for his role in the Ryuk ransomware conspiracy.
  2. Vardanyan specialized in gaining initial access to corporate networks, the entry point Ryuk affiliates used before deploying ransomware.
  3. Prosecutors tied Vardanyan's conspiracy window to over 2,400 attacks worldwide and roughly $15 million in ransom payments; the broader Ryuk campaign is estimated to have collected more than $150 million.
  4. He is at least the fourth Ryuk-linked defendant identified and prosecuted by U.S. authorities, following extraditions and arrests of Armenian and Ukrainian co-conspirators.
  5. Ryuk's core operators and other affiliates remain unidentified or uncharged, meaning the underlying threat model — initial access brokers feeding ransomware crews — persists today.
  6. Organizations should prioritize MFA, backup immutability, and precursor-malware detection over relying on law enforcement outcomes to deter future attacks.

Sources

  • Ryuk ransomware operator gets 2-year sentence after extorting victims for $1.2 million — The Record
  • US Court Sentences Armenian Man to Prison for Ryuk Ransomware Attacks — SecurityWeek
#Ransomware#Cybercrime#Ryuk#Law Enforcement

Related Articles

Armenian National Pleads Guilty to Ryuk Ransomware Attacks

Karen Vardanyan, an Armenian national, has pleaded guilty to federal charges related to Ryuk ransomware attacks and faces up to 15 years in prison with...

3 min read

Ryuk Ransomware Member Sentenced to 24 Months in Prison

Armenian national Karen Vardanyan got 24 months for Ryuk ransomware attacks that netted roughly 1,610 BTC from U.S. victims between 2019-2020.

3 min read

Ryuk Operator Pleads Guilty; BlackCat/AlphV Conspirator Gets Nearly 6-Year Sentence

A Ryuk ransomware operator pleaded guilty in Oregon federal court while a BlackCat/AlphV conspirator received a 70-month prison sentence in Florida,...

3 min read
Back to all News