Armenian National Karen Vardanyan Pleads Guilty to Ryuk Ransomware Conspiracy (District of Oregon) — Threadlinqs Intelligence
As of 2026-07-10, Armenian National Karen Vardanyan Pleads Guilty to Ryuk Ransomware Conspiracy (District of Oregon) is a high-severity ransomware threat attributed to Periwinkle Tempest (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 20 indicators of compromise.
Threat ID: TL-2026-1192 · Severity: HIGH · Status: RESOLVED · Category: RANSOMWARE
Attribution: Periwinkle Tempest · Russia · FINANCIAL
Karen Serobovich Vardanyan, a 34-year-old Armenian national extradited from Ukraine in June 2025, pleaded guilty in the U.S. District Court for the District of Oregon to conspiracy and computer fraud
This threat record documents a criminal-justice milestone rather than a new technical exploitation event: the guilty plea of Karen Serobovich Vardanyan for his role in the Ryuk ransomware conspiracy operated by the Wizard Spider (also tracked as UNC1878/Team9/Grim Spider) cybercrime enterprise. Vardanyan was arrested in Kyiv, Ukraine in April 2025, extradited to the United States on June 18-19, 2025, and initially faced a seven-day jury trial set for August 26, 2025 before entering a guilty plea (announced July 10, 2026) to one count of conspiracy to commit computer fraud/wire fraud/extortion and one count of computer fraud. He faces a statutory maximum of 15 years' imprisonment (5 years for conspiracy, 10 years for computer fraud), fines up to $500,000, and has agreed to pay over $1.1 million in restitution; sentencing is scheduled for September 22, 2026. Three additional defendants were charged in the same indictment: Levon Georgiyovych Avetisyan (Armenian national, in custody in France pending extradition), and Ukrainian nationals Oleg Nikolayevich Lyulyava and Andrii Leonydovich Prykhodchenko (both remain at large).
Prosecutors allege the conspirators gained unauthorized access to victim networks and deployed Ryuk ransomware onto compromised servers and workstations, then extorted ransom payments in exchange for decryption keys. Named/described victims include a Michigan-based company that paid 200 BTC (~$1.1-1.2 million) in January 2020, a technology company in Wilsonville, Oregon breached in December 2019 (data and credentials stolen), and a private school in Texas compromised in February 2020. Total conspiracy proceeds across reporting range from ~1,160 BTC (per the July 2026 plea announcement, >$15M at the time) to ~1,610 BTC (per the original July 2025 indictment covering a broader March 2019-September 2020 window).
Ryuk itself is a well-documented enterprise ransomware family first observed in August 2018 as a derivative of Hermes 2.1, operated by the Russia-based Wizard Spider criminal enterprise as part of a 'big game hunting' strategy targeting organizations with the financial capacity to pay large ransoms. Ryuk campaigns typically begin with phishing emails delivering TrickBot, BazarLoader (BazarBackdoor), or Emotet as initial loaders; operators then use PowerShell, Windows Management Instrumentation (WMI), Cobalt Strike, and stolen/harvested credentials to move laterally (frequently via SMB/Windows admin shares and RDP), conduct reconnaissance and data exfiltration, and finally deploy the Ryuk binary, dropping a ransom note (commonly named 'RyukReadMe'), stopping security/backup-related services (e.g., via net.exe stop commands against services like audioendpointbuilder, samss, and MSSQL instances), and encrypting files to extort victims. TrickBot's Anchor_DNS module has been documented performing outbound connectivity checks against legitimate IP-lookup services (ipecho.net, api.ipify.org, checkip.amazonaws.com, ip.anysrc.net, wtfismyip.com, ipinfo.io, icanhazip.com, myexternalip.com) as part of its DNS-tunneling C2 channel. CISA's joint advisory (AA20-302A) previously warned of an imminent, credible threat of Ryuk deployment against the U.S. healthcare and public-health sector in coordination with TrickBot and BazarLoader activity. Ryuk operations wound down around 2020-2021 as the Wizard Spider enterprise transitioned much of its ransomware activity to the Conti brand.
Target sectors: technology, education, privatesector
Target regions: North America
Detections & IOCs
As of 2026-08-10, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 20 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
RANSOMWARE, HIGH, threat intelligence, cybersecurity, T1134, T1547, T1059, T1486, T1685, T1083, T1222, T1490, T1082, T1036