A former member of the notorious Ryuk ransomware gang has pleaded guilty in a US court to hacking and deploying the malware on multiple corporate networks, including those of several American companies. The 34-year-old Armenian man, Karen Serobovich Vardanyan, faces up to 15 years in prison for his role in the scheme, which netted his co-conspirators an estimated $15 million in ransom payments.
Vardanyan’s involvement with Ryuk began in November 2019, when he and his co-conspirators started breaching corporate networks across the US. The group, known for its sophisticated tactics, would gain initial access to a network through phishing or other social engineering attacks before deploying the Ryuk malware to encrypt critical systems. This created a sense of urgency among victims, who were often forced to pay hefty ransoms to restore access to their data.
According to court documents, Vardanyan and his co-conspirators targeted several high-profile organizations, including a Michigan company that paid 200 BTC (worth over $1.1 million at the time) in ransom. Other victims included a technology firm in Oregon and a school in Texas. In total, the group is believed to have received around 1,610 bitcoins in ransom payments, valued at approximately $15 million.
The Ryuk gang’s operations were brought to an end in mid-2020, but its legacy lives on. Many of its members transitioned to other cybercrime groups, including Conti, which quickly became one of the most prolific hacker gangs before disbanding in 2022. The dismantling of these groups has left a power vacuum that continues to pose a threat to organizations worldwide.
Vardanyan’s guilty plea marks a significant milestone in the ongoing effort to hold cybercrime perpetrators accountable for their actions. His case highlights the importance of cybersecurity awareness and the need for organizations to prioritize threat detection and incident response capabilities. As Vardanyan prepares to face sentencing in September, his story serves as a reminder that those responsible for cyberattacks will ultimately be brought to justice.
For security teams seeking to improve their preparedness against ransomware attacks, this case underscores the importance of proactive defense strategies. By investing in robust threat detection and incident response capabilities, organizations can reduce their vulnerability to such attacks and mitigate the financial and reputational consequences of a successful breach.
Source: Bleeping Computer — 2026-07-10