Ryuk Member Karen Vardanyan Sentenced to Two Years in U.S. Prison

Ryuk member Karen Vardanyan was sentenced to 24 months in U.S. prison after extradition from Ukraine and ordered to pay $1.2M in restitution.
Karen Vardanyan, a 35-year-old Armenian citizen who went by “Maneeken” and, oddly, “Karl Lagerfeld” online, was extradited from Ukraine and sentenced to 24 months in federal prison plus three years of supervised release. He was also ordered to pay $1,219,106 in restitution to his victims.
“Karen Vardanyan, 35, was sentenced to 24 months in federal prison and 3 years’ supervised release. He was also ordered to pay $1,219,106.00 in restitution to the victims in the case.” states the press release by DoJ..
That number alone tells you the scale of what he was involved in, and it’s only a fraction of the total damage the wider conspiracy caused.
In July, Vardanyan pleaded guilty in the U.S. for his role in Ryuk ransomware attacks targeting American organizations between 2019 and 2020. Extradited from Ukraine after his 2025 arrest, he admitted providing initial access to corporate networks that enabled ransomware deployment.
Between November 2019 and April 2020, Karen Vardanyan illegally accessed corporate networks and helped deploy Ryuk ransomware on hundreds of servers and workstations.
The attacks encrypted victims’ data and demanded Bitcoin payments in exchange for decryption keys. Among the victims were a Michigan company that paid 200 Bitcoin (worth over $1.1 million at the time), a company in Oregon, and a school in Texas. Overall, the group is believed to have collected around 1,610 Bitcoin, valued at more than $15 million when the ransoms were paid.
According to a report published by Advanced-intel and HYAS in 2021, Ryuk was a highly profitable ransomware operation, generating an estimated $150 million in Bitcoin ransom payments. Researchers traced 61 wallet addresses linked to the group and identified laundering mechanisms involving brokers, intermediary wallets, and cryptocurrency exchanges such as Binance and Huobi. Ryuk RaaS was run by the crew known as Wizard Spider, which became one of the defining threats of the early pandemic years, hitting hospitals hard while healthcare systems were already stretched to breaking. At its peak, it was compromising roughly 20 organizations a week and pulled in more than $150 million in ransom payments before shutting down in 2020.
The operators used professional money-flow techniques and created unique ProtonMail addresses for each victim to improve operational security and avoid detection.
Hundreds of servers and workstations from a role that was, technically, just the entry point. That’s the part worth sitting with if you’re in charge of defending a network: the person who gets you in the door is rarely the one who does the flashy encryption work, but without them none of it happens.
The FBI investigated the case, and the Justice Department’s Office of International Affairs handled the extradition process, with Ukrainian authorities getting a direct thank you for their cooperation, a detail that matters more than it might seem given how often ransomware operators hide behind borders that don’t cooperate with US law enforcement.
Ryuk did not really disappear when the ransomware operation shut down. Wizard Spider later rebranded as Conti, which grew even bigger before its chats and source code leaked in 2022. The group then broke into smaller crews, some joining other ransomware operations and others creating new ones. The Ryuk-to-Conti connection is therefore still visible in today’s ransomware ecosystem.
Whether a 24-month sentence matches more than $1 million in restitution and a role in a $15 million conspiracy is open to debate. But the extradition itself sends a clear message: hiding behind national borders is no longer a guarantee of safety for cybercriminals.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
Pierluigi Paganini
(SecurityAffairs – hacking, Ryuk)

