Armenian Hacker Sentenced to 24 Months for Ryuk Ransomware Attack
An Armenian man has been sentenced to 24 months in prison and three years of supervised release for hacking a U.S. company and encrypting its systems in a Ryuk ransomware attack.
Karen Serovovich Vardanyan, also known online as “Mannyken” or “Karl Lagerfeld,” pleaded guilty in July. The 35-year-old, who specialized in gaining initial access to corporate networks, was extradited from Kyiv, Ukraine, after his arrest in April 2025.
According to court documents, Vardanyan hacked the networks of multiple U.S. organizations in Ryuk ransomware attacks carried out between March 2019 and June 2020.
Ryuk ransomware attackers demanded $1.1 million from Michigan company
In one attack, Vardanyan and an accomplice infiltrated a Michigan company and received a payment of 200 Bitcoin, worth more than $1.1 million at the time. Prosecutors said the cybercriminals also breached a school in Texas and a technology company in Wilsonville, Oregon.
“Vardanyan and his co-conspirators illegally accessed the victim companies’ computer networks and deployed ransomware to hundreds of compromised servers and workstations,” the U.S. Department of Justice stated.
“Vardanian and his co-conspirators allegedly received approximately 1,610 Bitcoins as ransom money from the victim companies, with a value of more than $15 million at the time of payment.”
Ryuk ransomware operation targeted organizations worldwide
Ryuk was a ransomware-as-a-service (RaaS) operation active from August 2018 through mid-2020. The group became notorious for large-scale attacks against the healthcare sector during the COVID-19 pandemic.
At its peak, the Ryuk ransomware group reportedly attacked approximately 20 victims each week and collected more than $150 million in ransom payments.
Ryuk’s operators later moved to Conti ransomware
After Ryuk shut down in 2020, the Wizard Spider cybercriminal organization behind the operation switched to Conti ransomware, which quickly became one of the most prolific hacker groups.
Conti also disbanded in 2022 after its internal chats and source code were leaked in May of that year. The leak split the organization into multiple smaller groups, some of which infiltrated existing ransomware gangs while others launched new operations.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a two-hour digital summit about what will change with AI-speed attacks, what defenders should stop doing, and how to verify, decide, fix, and revalidate at machine speed.
Source: www.bleepingcomputer.com



