Ryuk Ransomware Operator Sentenced for Deploying Malware and Extorting Victim Networks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


An Armenian national extradited from Ukraine to the United States has been sentenced to federal prison for his role in Ryuk ransomware attacks that targeted organizations worldwide, including a company in Oregon.

Karen Vardanyan, 35, received a 24-month federal prison sentence followed by 3 years of supervised release, according to the U.S. Attorney’s Office for the District of Oregon. The court also ordered him to pay $1,219,106 in restitution to victims affected by the ransomware extortion scheme.

Vardanyan was linked to a conspiracy that deployed Ryuk ransomware on victim networks between March 2019 and about June 2020. He allegedly used the online monikers “Maneeken” and “Karl Lagerfeld” while participating in the operation.

Ryuk ransomware encrypted files and disrupted access to computers and servers operated by targeted organizations. The attackers then demanded cryptocurrency payments, commonly Bitcoin, in exchange for restoring access to affected systems or providing decryption capabilities.

Ryuk Ransomware Operator Sentenced

Court records state that the conspiracy targeted companies, schools, and other entities worldwide. The group extorted more than $1 million from several victims. One identified victim was a company based in Wilsonville, Oregon.

The case highlights the international structure of major ransomware operations. Threat actors can operate across multiple countries while targeting victims in the United States and other regions.

They often rely on cryptocurrency payments, online aliases, remote infrastructure, and intermediaries to conceal their identities and move ransom proceeds.

A federal grand jury in Portland returned a superseding indictment charging Vardanyan on February 22, 2024. The indictment included charges of conspiracy, computer fraud, and computer extortion.

He was extradited from Ukraine and made his initial appearance in U.S. federal court on June 20, 2025. A magistrate judge ordered him detained following his appearance. On July 8, 2026, Vardanyan pleaded guilty to conspiracy and computer fraud.

Ryuk was one of the most disruptive ransomware families used against enterprise networks. Its operators and affiliates typically sought high-value targets where outages could create significant operational pressure.

Ransomware campaigns of this type can affect business operations, customer services, data availability, backup systems, and incident-response resources.

Organizations can reduce ransomware exposure by maintaining offline, tested backups, deploying multi-factor authentication, promptly patching internet-facing systems, restricting privileged access, and monitoring networks for suspicious encryption activity.

Security teams should also investigate unauthorized remote access, unusual credential use, disabled endpoint security controls, and rapid file-renaming activity.

The FBI investigated the case, while Assistant U.S. Attorney Katherine Rykken prosecuted it. The Justice Department’s Office of International Affairs helped secure Vardanyan’s arrest and extradition. U.S. authorities also credited Ukrainian authorities for their cooperation in the investigation.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

The post Ryuk Ransomware Operator Sentenced for Deploying Malware and Extorting Victim Networks appeared first on Cyber Security News.