An Armenian national involved in the notorious Ryuk ransomware operation has been sentenced to 24 months in a U.S. prison for helping attackers gain access to corporate networks and deploy ransomware against organizations across the United States.
Karen Serobovich Vardanyan, 35, also known online as “Maneeken” and “Karl Lagerfeld,” received the two-year prison sentence along with three years of supervised release. He pleaded guilty in July 2026 after being extradited from Kyiv, Ukraine, following his arrest in April 2025.
Vardanyan specialized in one of the most important stages of a ransomware attack: obtaining the initial access that allowed other members of the operation to move deeper into corporate networks.
Breaking Into Companies for RyukAccording to court documents, Vardanyan participated in Ryuk attacks against multiple U.S. organizations between March 2019 and approximately June 2020.
After obtaining unauthorized access, the group deployed ransomware across hundreds of compromised servers and workstations, encrypting systems and demanding cryptocurrency payments from victims.
One of the attacks targeted a company in Michigan that ultimately paid the attackers 200 Bitcoin, worth more than $1.1 million at the time.
Prosecutors also connected the group to attacks against a school in Texas and a technology company in Wilsonville, Oregon.
The U.S. Department of Justice previously said Vardanyan and his co-conspirators received approximately 1,610 Bitcoin in ransom payments, valued at more than $15 million when the payments were made.
Initial Access Was a Crucial Part of the OperationVardanyan’s role illustrates how mature ransomware groups divided their operations among specialists.
Rather than requiring every member to perform every stage of an intrusion, criminal organizations increasingly separated responsibilities between people responsible for gaining access, moving laterally through networks, stealing credentials, deploying ransomware and negotiating with victims.
Initial access specialists were particularly valuable because they provided the foothold needed for the rest of the attack.
Once inside a corporate environment, ransomware operators could compromise additional accounts and machines before eventually deploying encryption across large portions of the network.
This model helped ransomware evolve from relatively simple malware campaigns into organized cybercrime operations capable of attacking large enterprises and public institutions.
Ryuk Became One of the Most Notorious Ransomware GroupsRyuk emerged in 2018 and became one of the most successful ransomware operations of its era.
Unlike indiscriminate ransomware campaigns targeting individual computers, Ryuk focused heavily on organizations where operational disruption could create pressure to pay substantial ransom demands.
At its peak, the operation was reportedly compromising roughly 20 victims per week and ultimately collected more than $150 million in ransom payments.
The group became particularly notorious during the COVID-19 pandemic because of attacks targeting healthcare organizations.
Hospitals and healthcare networks represented especially sensitive targets because interruptions to computer systems could affect access to medical records and other essential services.
From Ryuk to ContiRyuk disappeared around the middle of 2020, but the criminal ecosystem behind it did not simply vanish.
The Wizard Spider cybercrime group associated with Ryuk subsequently moved toward the Conti ransomware operation.
Conti quickly became another dominant name in ransomware, attacking companies, governments and critical organizations around the world.
That operation eventually collapsed in 2022 after internal communications and source code were leaked. Rather than ending the underlying cybercrime activity, however, Conti’s members fragmented into smaller groups.
Some joined existing ransomware operations, while others established new groups.
The evolution from Ryuk to Conti and then into numerous smaller operations demonstrates one of the major difficulties facing law enforcement: dismantling a ransomware brand does not necessarily dismantle the people, infrastructure and expertise behind it.
Years Later, Ransomware Investigations ContinueVardanyan’s sentencing also demonstrates the long timeline of international cybercrime investigations.
The attacks occurred primarily between 2019 and 2020, but his arrest did not take place until 2025. Extradition, prosecution and sentencing extended the process even further.
Cybercriminals frequently operate across multiple jurisdictions, making arrests dependent on international cooperation and the ability of authorities to locate suspects in countries willing to detain and extradite them.
Cryptocurrency transactions, infrastructure records and other digital evidence can nevertheless allow investigators to continue pursuing participants years after a ransomware operation disappears.
Ryuk itself may no longer exist, but law enforcement investigations into the people who helped operate it continue.
The sentencing of one of its initial-access specialists shows that the consequences of participating in major ransomware campaigns can arrive long after the malware, infrastructure and criminal brand have disappeared.