Ryuk Ransomware Operative Sentenced to 24 Months for Attacks on US Companies
A 35-year-old Armenian man, Karen Serobovich Vardanyan, receives a 24-month prison sentence and three years of supervised release for his role in Ryuk ransomware attacks against U.S. companies. Known online as "Maneeken," Vardanyan pleads guilty in July after being extradited from Kyiv, Ukraine, following his April 2025 arrest. He specializes in gaining initial access to corporate networks.
According to court documents, Vardanyan hacks into the networks of multiple U.S. organizations between March 2019 and June 2020. In one attack, he and his accomplices breach a Michigan company that pays 200 BTC, worth over $1.1 million at the time. Prosecutors say the group also targets a Texas school and an Oregon technology company. The DOJ states the conspirators receive approximately 1,610 bitcoins in ransoms, valued at over $15 million.
Ryuk operates as a ransomware-as-a-service scheme from August 2018 to mid-2020, becoming notorious for attacking the healthcare sector during the COVID-19 pandemic. At its peak, the group compromises roughly 20 victims weekly, collecting more than $150 million in ransoms. After Ryuk shuts down, the Wizard Spider gang behind it moves to Conti ransomware, which disbands in 2022 following major leaks and splinters into smaller criminal units.