Trusence Technology, daily
Last updated 26 September 2026 Türkçe
← All stories
Security

Ryuk ransomware operator sentenced to two years in U.S. prison

The case highlights how U.S. authorities are pursuing individuals behind major ransomware groups even years after their attacks.

A 35-year-old Armenian operator linked to the Ryuk ransomware-as-a-service operation has been sentenced in the U.S. to 24 months in prison and three years of supervised release for hacking American organizations and encrypting their systems. Karen Serobovich Vardanyan, known online as “Maneeken” and “Karl Lagerfeld,” admitted to specializing in initial access to corporate networks and pleaded guilty after being extradited from Kyiv following his April 2025 arrest. Court filings state that between March 2019 and June 2020 he helped compromise multiple U.S. entities, including a Michigan firm that paid 200 BTC (over $1.1 million then), a Texas school, and an Oregon technology company. Prosecutors say the Ryuk crew received roughly 1,610 BTC in ransom payments worth more than $15 million at the time, and at its height the group was hitting about 20 victims weekly and ultimately extracted over $150 million. After Ryuk ceased operations in 2020, its operators, the Wizard Spider group, pivoted to Conti ransomware, which itself dissolved in 2022 after major leaks and fragmented into smaller crews that joined or founded other ransomware outfits.

Why it matters

This sentencing shows that people involved in large ransomware schemes can still face prosecution long after an operation winds down, even if they were working from abroad. Vardanyan’s role in breaking into U.S. organizations and helping deploy Ryuk against companies, a school and a technology firm illustrates how broad the victim set was, and the scale of ransom payments underscores why law enforcement continues to track down operators tied to groups like Ryuk and its successors.

Sources

  • BleepingComputer