Armenian National Karen Vardanyan Pleads Guilty to Ryuk Ransomware Conspiracy (District of Oregon)

Armenian National Karen Vardanyan Pleads Guilty to Ryuk (TL-2026-1192), also tracked as Ryuk Ransomware Conspiracy Case, is a high-severity ransomware operation, first published 2026-07-10. It is attributed to Periwinkle Tempest (Russia) with high confidence, affects Unknown Enterprise Windows networks (unnamed Michigan-based company), maps to 24 MITRE ATT&CK techniques (T1003, T1016, T1021), and is covered by 9 detection rules and 20 indicators of compromise.

Key facts for TL-2026-1192

Threat ID
TL-2026-1192
Also known as
Ryuk Ransomware Conspiracy Case, United States v. Vardanyan
Severity
HIGH
Status
RESOLVED
Category
RANSOMWARE
First published
2026-07-10
Last reviewed
2026-07-10
Attribution
Periwinkle Tempest
Attribution confidence
HIGH
Nation-state nexus
Russia
Motivation
FINANCIAL
Target sectors
technology, education, privatesector
Target regions
North America
Detection rules
9
Indicators of compromise
20

Malware and tooling in Armenian National Karen Vardanyan Pleads Guilty to Ryuk

Malware and tooling: Anchor - S0504, BazarBackdoor, Emotet - S0367, Ryuk, TrickBot, Cobalt Strike

Karen Serobovich Vardanyan, a 34-year-old Armenian national extradited from Ukraine in June 2025, pleaded guilty in the U.S. District Court for the District of Oregon to conspiracy and computer fraud for deploying Ryuk ransomware against at least five U.S. companies and a Texas private school between November 2019 and April 2020. He and co-conspirators extorted roughly 1,160-1,610 bitcoins (valued at over $15 million at the time) in ransom payments; a Michigan victim alone paid 200 BTC (~$1.1-1.2 million).

How Armenian National Karen Vardanyan Pleads Guilty to Ryuk works

This threat record documents a criminal-justice milestone rather than a new technical exploitation event: the guilty plea of Karen Serobovich Vardanyan for his role in the Ryuk ransomware conspiracy operated by the Wizard Spider (also tracked as UNC1878/Team9/Grim Spider) cybercrime enterprise. Vardanyan was arrested in Kyiv, Ukraine in April 2025, extradited to the United States on June 18-19, 2025, and initially faced a seven-day jury trial set for August 26, 2025 before entering a guilty plea (announced July 10, 2026) to one count of conspiracy to commit computer fraud/wire fraud/extortion and one count of computer fraud. He faces a statutory maximum of 15 years' imprisonment (5 years for conspiracy, 10 years for computer fraud), fines up to $500,000, and has agreed to pay over $1.1 million in restitution; sentencing is scheduled for September 22, 2026. Three additional defendants were charged in the same indictment: Levon Georgiyovych Avetisyan (Armenian national, in custody in France pending extradition), and Ukrainian nationals Oleg Nikolayevich Lyulyava and Andrii Leonydovich Prykhodchenko (both remain at large).

Prosecutors allege the conspirators gained unauthorized access to victim networks and deployed Ryuk ransomware onto compromised servers and workstations, then extorted ransom payments in exchange for decryption keys. Named/described victims include a Michigan-based company that paid 200 BTC (~$1.1-1.2 million) in January 2020, a technology company in Wilsonville, Oregon breached in December 2019 (data and credentials stolen), and a private school in Texas compromised in February 2020. Total conspiracy proceeds across reporting range from ~1,160 BTC (per the July 2026 plea announcement, >$15M at the time) to ~1,610 BTC (per the original July 2025 indictment covering a broader March 2019-September 2020 window).

Ryuk itself is a well-documented enterprise ransomware family first observed in August 2018 as a derivative of Hermes 2.1, operated by the Russia-based Wizard Spider criminal enterprise as part of a 'big game hunting' strategy targeting organizations with the financial capacity to pay large ransoms. Ryuk campaigns typically begin with phishing emails delivering TrickBot, BazarLoader (BazarBackdoor), or Emotet as initial loaders; operators then use PowerShell, Windows Management Instrumentation (WMI), Cobalt Strike, and stolen/harvested credentials to move laterally (frequently via SMB/Windows admin shares and RDP), conduct reconnaissance and data exfiltration, and finally deploy the Ryuk binary, dropping a ransom note (commonly named 'RyukReadMe'), stopping security/backup-related services (e.g., via net.exe stop commands against services like audioendpointbuilder, samss, and MSSQL instances), and encrypting files to extort victims. TrickBot's Anchor_DNS module has been documented performing outbound connectivity checks against legitimate IP-lookup services (ipecho.net, api.ipify.org, checkip.amazonaws.com, ip.anysrc.net, wtfismyip.com, ipinfo.io, icanhazip.com, myexternalip.com) as part of its DNS-tunneling C2 channel. CISA's joint advisory (AA20-302A) previously warned of an imminent, credible threat of Ryuk deployment against the U.S. healthcare and public-health sector in coordination with TrickBot and BazarLoader activity. Ryuk operations wound down around 2020-2021 as the Wizard Spider enterprise transitioned much of its ransomware activity to the Conti brand.

MITRE ATT&CK techniques used in TL-2026-1192

Credential Access

T1003 OS Credential Dumping

Discovery

T1016 System Network Configuration Discovery; T1057 Process Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery

Lateral Movement

T1021 Remote Services

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1055 Process Injection; T1078 Valid Accounts

Exfiltration

T1041 Exfiltration Over C2 Channel

Execution

T1053 Scheduled Task/Job; T1059 Command and Scripting Interpreter; T1106 Native API

Initial Access

T1133 External Remote Services; T1566 Phishing

Privilege Escalation

T1134 Access Token Manipulation

defense-impairment

T1222 File and Directory Permissions Modification; T1685 Disable or Modify Tools

Impact

T1486 Data Encrypted for Impact; T1489 Service Stop; T1490 Inhibit System Recovery

Persistence

T1547 Boot or Logon Autostart Execution

Command and Control

T1568 Dynamic Resolution

Affected products and versions in Armenian National Karen Vardanyan Pleads Guilty to Ryuk

  • Unknown — Enterprise Windows networks (unnamed Michigan-based company)
    Vulnerable versions: victim environment, January 2020
  • Unknown — Technology company network, Wilsonville, Oregon
    Vulnerable versions: victim environment, December 2019
  • Unknown — Private school network, Texas
    Vulnerable versions: victim environment, February 2020

Remediation for Armenian National Karen Vardanyan Pleads Guilty to Ryuk

Immediate actions

  • Disable or restrict RDP exposure to the internet; enforce MFA and account lockout on all remote access services
  • Block outbound access to known TrickBot/BazarLoader C2 infrastructure and monitor for Anchor_DNS-style DNS tunneling to IP-lookup services
  • Isolate and rebuild any host showing TrickBot, BazarLoader, or Emotet loader activity before ransomware deployment occurs
  • Preserve and monitor for the 'RyukReadMe' ransom-note artifact and net.exe service-stop command sequences as late-stage indicators

Workarounds

  • Restrict SMB (445/tcp) and RDP (3389/tcp) between workstation and server VLANs where legacy segmentation prevents full patching/hardening

Longer-term hardening

  • Deploy EDR with behavioral detection for Cobalt Strike beaconing, WMI-based lateral movement, and mass file encryption
  • Maintain offline, tested, immutable backups to eliminate ransom leverage
  • Segment networks to limit SMB/Windows-admin-share lateral movement between business-critical systems
  • Adopt phishing-resistant email filtering and user training targeting malicious-attachment-based loader delivery

Timeline of Armenian National Karen Vardanyan Pleads Guilty to Ryuk

  • Ryuk ransomware first observed in the wild, a derivative of Hermes 2.1 ransomware, operated by the Wizard Spider cybercrime enterprise.
  • Per the original July 2025 indictment, Vardanyan and co-conspirators began infiltrating victim networks to deploy Ryuk ransomware (broader charged window: March 2019-September 2020).
  • Per the guilty plea, Vardanyan's admitted deployment of Ryuk ransomware against U.S. victims begins (November 2019).
  • A technology company in Wilsonville, Oregon is breached; data and credentials are stolen ahead of ransomware deployment.
  • A Michigan-based company pays approximately 200 bitcoin (~$1.1-1.2 million at the time) in ransom to restore network access.
  • A private school in Texas is breached and hit with Ryuk ransomware.
  • Admitted conspiracy period in the guilty plea ends (April 2020); conspirators are alleged to have collected approximately 1,160-1,610 bitcoins in total ransom proceeds, valued at over $15 million at the time.
  • Karen Vardanyan is arrested in Kyiv, Ukraine.
  • Vardanyan is extradited from Ukraine to the United States; he appears in U.S. federal court the following day.
  • DOJ publicly announces federal charges against Vardanyan (conspiracy, computer fraud, extortion) following his extradition; co-conspirators Avetisyan, Lyulyava, and Prykhodchenko are also charged.
  • A seven-day jury trial is scheduled to begin in the U.S. District Court for the District of Oregon.
  • Vardanyan pleads guilty in Oregon federal court to conspiracy and computer fraud, agreeing to pay over $1.1 million in restitution.
  • U.S. Attorney's Office for the District of Oregon and press outlets publicly announce the guilty plea.
  • Sentencing hearing scheduled before a U.S. District Court judge in Oregon; Vardanyan faces up to 15 years' imprisonment and $500,000 in fines.

Sources cited for Armenian National Karen Vardanyan Pleads Guilty to Ryuk

Threats related to Armenian National Karen Vardanyan Pleads Guilty to Ryuk

Detection coverage for TL-2026-1192

As of 2026-07-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1192 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats