Armenian National Karen Vardanyan Pleads Guilty to Ryuk Ransomware Conspiracy (District of Oregon)
Armenian National Karen Vardanyan Pleads Guilty to Ryuk (TL-2026-1192), also tracked as Ryuk Ransomware Conspiracy Case, is a high-severity ransomware operation, first published 2026-07-10. It is attributed to Periwinkle Tempest (Russia) with high confidence, affects Unknown Enterprise Windows networks (unnamed Michigan-based company), maps to 24 MITRE ATT&CK techniques (T1003, T1016, T1021), and is covered by 9 detection rules and 20 indicators of compromise.
Key facts for TL-2026-1192
- Threat ID
- TL-2026-1192
- Also known as
- Ryuk Ransomware Conspiracy Case, United States v. Vardanyan
- Severity
- HIGH
- Status
- RESOLVED
- Category
- RANSOMWARE
- First published
- 2026-07-10
- Last reviewed
- 2026-07-10
- Attribution
- Periwinkle Tempest
- Attribution confidence
- HIGH
- Nation-state nexus
- Russia
- Motivation
- FINANCIAL
- Target sectors
- technology, education, privatesector
- Target regions
- North America
- Detection rules
- 9
- Indicators of compromise
- 20
Malware and tooling in Armenian National Karen Vardanyan Pleads Guilty to Ryuk
Malware and tooling: Anchor - S0504, BazarBackdoor, Emotet - S0367, Ryuk, TrickBot, Cobalt Strike
Karen Serobovich Vardanyan, a 34-year-old Armenian national extradited from Ukraine in June 2025, pleaded guilty in the U.S. District Court for the District of Oregon to conspiracy and computer fraud for deploying Ryuk ransomware against at least five U.S. companies and a Texas private school between November 2019 and April 2020. He and co-conspirators extorted roughly 1,160-1,610 bitcoins (valued at over $15 million at the time) in ransom payments; a Michigan victim alone paid 200 BTC (~$1.1-1.2 million).
How Armenian National Karen Vardanyan Pleads Guilty to Ryuk works
This threat record documents a criminal-justice milestone rather than a new technical exploitation event: the guilty plea of Karen Serobovich Vardanyan for his role in the Ryuk ransomware conspiracy operated by the Wizard Spider (also tracked as UNC1878/Team9/Grim Spider) cybercrime enterprise. Vardanyan was arrested in Kyiv, Ukraine in April 2025, extradited to the United States on June 18-19, 2025, and initially faced a seven-day jury trial set for August 26, 2025 before entering a guilty plea (announced July 10, 2026) to one count of conspiracy to commit computer fraud/wire fraud/extortion and one count of computer fraud. He faces a statutory maximum of 15 years' imprisonment (5 years for conspiracy, 10 years for computer fraud), fines up to $500,000, and has agreed to pay over $1.1 million in restitution; sentencing is scheduled for September 22, 2026. Three additional defendants were charged in the same indictment: Levon Georgiyovych Avetisyan (Armenian national, in custody in France pending extradition), and Ukrainian nationals Oleg Nikolayevich Lyulyava and Andrii Leonydovich Prykhodchenko (both remain at large).
Prosecutors allege the conspirators gained unauthorized access to victim networks and deployed Ryuk ransomware onto compromised servers and workstations, then extorted ransom payments in exchange for decryption keys. Named/described victims include a Michigan-based company that paid 200 BTC (~$1.1-1.2 million) in January 2020, a technology company in Wilsonville, Oregon breached in December 2019 (data and credentials stolen), and a private school in Texas compromised in February 2020. Total conspiracy proceeds across reporting range from ~1,160 BTC (per the July 2026 plea announcement, >$15M at the time) to ~1,610 BTC (per the original July 2025 indictment covering a broader March 2019-September 2020 window).
Ryuk itself is a well-documented enterprise ransomware family first observed in August 2018 as a derivative of Hermes 2.1, operated by the Russia-based Wizard Spider criminal enterprise as part of a 'big game hunting' strategy targeting organizations with the financial capacity to pay large ransoms. Ryuk campaigns typically begin with phishing emails delivering TrickBot, BazarLoader (BazarBackdoor), or Emotet as initial loaders; operators then use PowerShell, Windows Management Instrumentation (WMI), Cobalt Strike, and stolen/harvested credentials to move laterally (frequently via SMB/Windows admin shares and RDP), conduct reconnaissance and data exfiltration, and finally deploy the Ryuk binary, dropping a ransom note (commonly named 'RyukReadMe'), stopping security/backup-related services (e.g., via net.exe stop commands against services like audioendpointbuilder, samss, and MSSQL instances), and encrypting files to extort victims. TrickBot's Anchor_DNS module has been documented performing outbound connectivity checks against legitimate IP-lookup services (ipecho.net, api.ipify.org, checkip.amazonaws.com, ip.anysrc.net, wtfismyip.com, ipinfo.io, icanhazip.com, myexternalip.com) as part of its DNS-tunneling C2 channel. CISA's joint advisory (AA20-302A) previously warned of an imminent, credible threat of Ryuk deployment against the U.S. healthcare and public-health sector in coordination with TrickBot and BazarLoader activity. Ryuk operations wound down around 2020-2021 as the Wizard Spider enterprise transitioned much of its ransomware activity to the Conti brand.
MITRE ATT&CK techniques used in TL-2026-1192
Credential Access
Discovery
T1016 System Network Configuration Discovery; T1057 Process Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery
Lateral Movement
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1055 Process Injection; T1078 Valid Accounts
Exfiltration
T1041 Exfiltration Over C2 Channel
Execution
T1053 Scheduled Task/Job; T1059 Command and Scripting Interpreter; T1106 Native API
Initial Access
T1133 External Remote Services; T1566 Phishing
Privilege Escalation
T1134 Access Token Manipulation
defense-impairment
T1222 File and Directory Permissions Modification; T1685 Disable or Modify Tools
Impact
T1486 Data Encrypted for Impact; T1489 Service Stop; T1490 Inhibit System Recovery
Persistence
T1547 Boot or Logon Autostart Execution
Command and Control
Affected products and versions in Armenian National Karen Vardanyan Pleads Guilty to Ryuk
- Unknown — Enterprise Windows networks (unnamed Michigan-based company)
Vulnerable versions: victim environment, January 2020 - Unknown — Technology company network, Wilsonville, Oregon
Vulnerable versions: victim environment, December 2019 - Unknown — Private school network, Texas
Vulnerable versions: victim environment, February 2020
Remediation for Armenian National Karen Vardanyan Pleads Guilty to Ryuk
Immediate actions
- Disable or restrict RDP exposure to the internet; enforce MFA and account lockout on all remote access services
- Block outbound access to known TrickBot/BazarLoader C2 infrastructure and monitor for Anchor_DNS-style DNS tunneling to IP-lookup services
- Isolate and rebuild any host showing TrickBot, BazarLoader, or Emotet loader activity before ransomware deployment occurs
- Preserve and monitor for the 'RyukReadMe' ransom-note artifact and net.exe service-stop command sequences as late-stage indicators
Workarounds
- Restrict SMB (445/tcp) and RDP (3389/tcp) between workstation and server VLANs where legacy segmentation prevents full patching/hardening
Longer-term hardening
- Deploy EDR with behavioral detection for Cobalt Strike beaconing, WMI-based lateral movement, and mass file encryption
- Maintain offline, tested, immutable backups to eliminate ransom leverage
- Segment networks to limit SMB/Windows-admin-share lateral movement between business-critical systems
- Adopt phishing-resistant email filtering and user training targeting malicious-attachment-based loader delivery
Timeline of Armenian National Karen Vardanyan Pleads Guilty to Ryuk
- Ryuk ransomware first observed in the wild, a derivative of Hermes 2.1 ransomware, operated by the Wizard Spider cybercrime enterprise.
- Per the original July 2025 indictment, Vardanyan and co-conspirators began infiltrating victim networks to deploy Ryuk ransomware (broader charged window: March 2019-September 2020).
- Per the guilty plea, Vardanyan's admitted deployment of Ryuk ransomware against U.S. victims begins (November 2019).
- A technology company in Wilsonville, Oregon is breached; data and credentials are stolen ahead of ransomware deployment.
- A Michigan-based company pays approximately 200 bitcoin (~$1.1-1.2 million at the time) in ransom to restore network access.
- A private school in Texas is breached and hit with Ryuk ransomware.
- Admitted conspiracy period in the guilty plea ends (April 2020); conspirators are alleged to have collected approximately 1,160-1,610 bitcoins in total ransom proceeds, valued at over $15 million at the time.
- Karen Vardanyan is arrested in Kyiv, Ukraine.
- Vardanyan is extradited from Ukraine to the United States; he appears in U.S. federal court the following day.
- DOJ publicly announces federal charges against Vardanyan (conspiracy, computer fraud, extortion) following his extradition; co-conspirators Avetisyan, Lyulyava, and Prykhodchenko are also charged.
- A seven-day jury trial is scheduled to begin in the U.S. District Court for the District of Oregon.
- Vardanyan pleads guilty in Oregon federal court to conspiracy and computer fraud, agreeing to pay over $1.1 million in restitution.
- U.S. Attorney's Office for the District of Oregon and press outlets publicly announce the guilty plea.
- Sentencing hearing scheduled before a U.S. District Court judge in Oregon; Vardanyan faces up to 15 years' imprisonment and $500,000 in fines.
Sources cited for Armenian National Karen Vardanyan Pleads Guilty to Ryuk
- Armenian national pleads guilty in Ryuk ransomware case
- District of Oregon | Armenian National Extradited to the United States Pleads Guilty to Ransomware Extortion Conspiracy
- Ryuk operator pleads guilty; Blackcat/AlphV conspirator gets nearly 6-year sentence
- Ryuk ransomware operator extradited to US, faces five years in federal prison
- Ryuk Ransomware Indictments: U.S. Charges Armenian and Ukrainian Nationals in Global Ransomware
- Armenian National Extradited to the United States Faces Federal Charges for Ransomware Extortion Conspiracy
- Ransomware Activity Targeting the Healthcare and Public Health Sector (AA20-302A)
- Ryuk, Software S0446 | MITRE ATT&CK
- Threat Assessment: Ryuk Ransomware
- Ryuk Ransomware Threat Actor Profile - Big Game Hunting TTPs
Threats related to Armenian National Karen Vardanyan Pleads Guilty to Ryuk
Detection coverage for TL-2026-1192
As of 2026-07-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1192 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.