A notorious Ryuk ransomware member has been sentenced to two years in prison and three years of supervised release for orchestrating devastating cyberattacks on US companies. Karen Serobovich Vardanyan, also known online as “Maneeken” or “Karl Lagerfeld,” pleaded guilty in July after being extradited from Ukraine following his April 2025 arrest.
Vardanyan’s involvement in the Ryuk ransomware operation is a significant blow to the notorious group. For those unfamiliar, Ryuk was a ransomware-as-a-service (RaaS) operation that went active in August 2018 and became infamous for its massive wave of attacks targeting the healthcare sector during the COVID-19 pandemic. At its peak, the Ryuk gang hacked around 20 victims every week, collecting more than $150 million in ransoms.
The US Department of Justice alleges that Vardanyan was responsible for hacking into multiple US organizations between March 2019 and June 2020 using his expertise in gaining initial access to corporate networks. One particularly high-profile attack involved a Michigan company that paid 200 BTC (worth over $1.1 million at the time) after being breached by Vardanyan and his accomplices. The group also targeted a school in Texas and a technology company in Oregon, deploying ransomware on hundreds of compromised servers and workstations.
As part of their operations, Vardanyan and his co-conspirators allegedly received approximately 1,610 bitcoins in ransom payments from the victim companies, valued at over $15 million at the time. This staggering sum highlights the devastating impact of Ryuk’s activities on businesses worldwide.
The Ryuk group’s shutdown in 2020 led to a significant shift in the cybercrime landscape, with its Wizard Spider creators transitioning to Conti ransomware. However, Conti too eventually disbanded in 2022 after its internal chats and source code were leaked online, fragmenting into multiple smaller units that infiltrated existing gangs or launched new operations.
This sentencing serves as a reminder of the consequences for individuals involved in orchestrating devastating cyberattacks on unsuspecting organizations. As the cybersecurity landscape continues to evolve, it’s crucial for businesses to prioritize robust security measures, including regular software updates, employee training, and robust backup procedures, to mitigate the risk of such attacks.
In light of this case, it’s essential for readers to understand that ransomware attacks are often the result of a complex chain of events. To protect yourself and your organization from similar threats, focus on maintaining strong network hygiene, implementing robust security controls, and staying informed about emerging trends in the cybercrime landscape.
Source: Bleeping Computer — 2026-09-23