Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
New RSA Attack Bypasses Factoring Keys
September 24, 2026
AvisLoader Malware Adapts to Survive Server Takedowns
September 24, 2026
Konni Malware Targets Ukraine Organizations with Fake PDF Files
September 24, 2026
Home/CyberSecurity News/Ryuk Ransomware Operator Sentenced for Deploying Malware and Extortion
CyberSecurity News

Ryuk Ransomware Operator Sentenced for Deploying Malware and Extortion

Key Takeaways An Armenian national, Karen Vardanyan, has been sentenced to 24 months in federal prison for his involvement in Ryuk ransomware attacks. Vardanyan, known online as...

Marcus Rodriguez
Marcus Rodriguez
September 23, 2026 3 Min Read
12 0

Key Takeaways

  • An Armenian national, Karen Vardanyan, has been sentenced to 24 months in federal prison for his involvement in Ryuk ransomware attacks.
  • Vardanyan, known online as “Maneeken” and “Karl Lagerfeld,” conspired to deploy Ryuk ransomware globally between March 2019 and June 2020.
  • He is ordered to pay over $1.2 million in restitution to victims, including an Oregon-based company.
  • The case highlights the complex, international nature of ransomware operations and the ongoing efforts by law enforcement to pursue threat actors across borders.

Ryuk Ransomware Operator Receives Federal Prison Sentence

A federal court has sentenced an Armenian national to two years in prison for his role in a global Ryuk ransomware scheme. Karen Vardanyan, 35, was extradited from Ukraine to the United States to face charges related to deploying the potent malware against various organizations worldwide, including an entity in Oregon.

Table Of Content

  • Key Takeaways
  • Ryuk Ransomware Operator Receives Federal Prison Sentence
  • Details of the Sentencing and Charges
  • International Scope of Ransomware Operations
  • The Impact of Ryuk Ransomware
  • What You Should Do

Details of the Sentencing and Charges

The U.S. Attorney’s Office for the District of Oregon announced that Vardanyan received a 24-month federal prison term, followed by three years of supervised release. Additionally, the court mandated that he pay $1,219,106 in restitution to victims impacted by the ransomware extortion. Vardanyan was implicated in a conspiracy that leveraged Ryuk ransomware on victim networks from approximately March 2019 to June 2020. During this period, he allegedly operated under the online aliases “Maneeken” and “Karl Lagerfeld.”

Ryuk ransomware is known for its ability to encrypt files and disrupt access to critical computer systems and servers. The attackers would subsequently demand cryptocurrency payments, typically Bitcoin, to restore access or provide decryption tools. Court records state that the conspiracy targeted a broad spectrum of victims, including companies, schools, and other institutions globally, extorting over $1 million. A Wilsonville, Oregon-based company was among the identified victims.

International Scope of Ransomware Operations

This case underscores the sophisticated, international framework often employed by major ransomware groups. Threat actors frequently operate across multiple countries, targeting victims in the United States and other regions while using various methods to obscure their identities and launder ransom proceeds. These methods often include cryptocurrency payments, online aliases, remote infrastructure, and a network of intermediaries.

A federal grand jury in Portland issued a superseding indictment against Vardanyan on February 22, 2024, which included charges of conspiracy, computer fraud, and computer extortion. After his extradition from Ukraine, Vardanyan made his initial appearance in U.S. federal court on June 20, 2025, where a magistrate judge ordered his detention. He pleaded guilty to conspiracy and computer fraud on July 8, 2026.

The Impact of Ryuk Ransomware

Ryuk was historically one of the most destructive ransomware families, frequently targeting high-value enterprise networks where operational disruptions could exert significant pressure. Such ransomware campaigns can severely impact business operations, customer services, data availability, backup systems, and incident response capabilities.

The Federal Bureau of Investigation (FBI) led the investigation, with Assistant U.S. Attorney Katherine Rykken prosecuting the case. The Justice Department’s Office of International Affairs played a crucial role in securing Vardanyan’s arrest and extradition, and U.S. authorities acknowledged the significant cooperation from Ukrainian authorities throughout the investigation.

What You Should Do

  • Maintain Offline, Tested Backups: Regularly back up critical data and store copies offline and off-site to ensure recovery without paying a ransom.
  • Implement Multi-Factor Authentication (MFA): Enable MFA for all accounts, especially for remote access, VPNs, and privileged accounts, to prevent unauthorized access.
  • Patch Internet-Facing Systems Promptly: Keep all operating systems, software, and applications, particularly those exposed to the internet, updated with the latest security patches.
  • Restrict Privileged Access: Implement the principle of least privilege, granting users only the necessary access for their roles and regularly reviewing permissions.
  • Monitor Networks for Suspicious Activity: Deploy robust network monitoring tools to detect unusual encryption activity, unauthorized remote access, unusual credential use, or disabled endpoint security controls.
  • Develop an Incident Response Plan: Create and regularly test a comprehensive incident response plan for ransomware attacks, including communication strategies and recovery procedures.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackMalwarePatchransomwareSecurityThreat

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

Critical AWS Lambda Flaw Bypasses IAM, Exposes Cloud Services

Next Post

Critical IBM FTM Flaws Let Attackers Execute Code and Access Payment Systems

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
OpenAI Agent Did Not Hack Australian Medicare Portal, Vendor Clarifies
September 24, 2026
Galago Ransomware Emerges, Linked to Panzer Group
September 24, 2026
Critical Check Point VPN Flaws Let Attackers Gain Remote Access Without Login
September 24, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us