Ryuk Ransomware Initial Access Operator Karen Vardanyan ("Maneeken") Sentenced to 24 Months in U.S. Federal Prison

Ryuk Ransomware Initial Access Operator Karen Vardanyan (TL-2026-2634), also tracked as Ryuk, is a medium-severity ransomware operation, first published 2026-09-23. It is attributed to Karen Vardanyan with high confidence, affects Microsoft Windows (servers and workstations in victim enterprise, maps to 21 MITRE ATT&CK techniques (T1003.001, T1018, T1021.001), and is covered by 9 detection rules and 29 indicators of compromise.

Key facts for TL-2026-2634

Threat ID
TL-2026-2634
Also known as
Ryuk, United States v. Vardanyan (D. Or.)
Severity
MEDIUM
Status
TRACKING
Category
RANSOMWARE
First published
2026-09-23
Last reviewed
2026-09-23
Attribution
Karen Vardanyan
Attribution confidence
HIGH
Motivation
FINANCIAL
Target sectors
technology, manufacturing, education, health, government administration, municipalities, enterprise
Target regions
North America, united states of america, Global
Detection rules
9
Indicators of compromise
29

Malware and tooling in Ryuk Ransomware Initial Access Operator Karen Vardanyan

Malware and tooling: BazarBackdoor, Cobalt Strike, Conti, LockerGoga, MegaCortex, MimiKatz, Ryuk, Ryuk ransomware, TrickBot, AdFind - S0552, BloodHound - S0521, Cobalt Strike

Karen Serobovich Vardanyan, a 35-year-old Armenian national extradited from Ukraine, was sentenced on September 22, 2026 in the U.S. District Court for the District of Oregon to 24 months in prison, 3 years of supervised release and $1,219,106 in restitution for his role in a Ryuk ransomware conspiracy active from March 2019 to about June 2020. Vardanyan, who operated as an initial access specialist under the monikers "Maneeken" and "Karl Lagerfeld", illegally accessed victim networks and helped deploy Ryuk on compromised servers and workstations; three co-defendants (Levon Avetisyan, Oleg Lyulyava, Andrii Prykhodchenko) remain charged.

How Ryuk Ransomware Initial Access Operator Karen Vardanyan works

OVERVIEW On September 22, 2026, U.S. Attorney Scott E. Bradford for the District of Oregon announced that Karen Serobovich Vardanyan, 35, an Armenian national, was sentenced to 24 months in federal prison followed by 3 years of supervised release and ordered to pay $1,219,106.00 in restitution to victims. Vardanyan will face removal from the United States after serving his sentence. On July 8, 2026 he pleaded guilty to conspiracy and fraud in connection with computers; the plea carried a statutory maximum of 15 years. The case was investigated by the FBI and prosecuted by Assistant U.S. Attorney Katherine Rykken, with the Justice Department's Office of International Affairs securing extradition and Ukrainian authorities providing assistance.

CHARGES AND PROCEDURAL HISTORY A federal grand jury in Portland returned a superseding indictment on February 22, 2024 charging Vardanyan and co-conspirators with conspiracy, fraud in connection with computers, and extortion in connection with computers. Co-defendants named in the indictment are Levon Georgiyovych Avetisyan (45, Armenian national) and Oleg Nikolayevich Lyulyava and Andrii Leonydovich Prykhodchenko (both 53, Ukrainian nationals). Vardanyan was arrested at his home in Kyiv in April 2025 at the request of the FBI (Ukraine's Office of the Prosecutor General described him as an initial access specialist who searched for vulnerabilities in corporate networks and passed the access to accomplices who then carried out the attacks), was extradited on June 18, 2025, and made his initial appearance in Portland federal court on June 20, 2025. Ukrainian authorities reported that he was identified through forensic analysis of equipment seized in the November 21, 2023 multinational raid in Ukraine (Ukrainian National Police with investigators from Norway, France, Germany and the United States, supported by Europol and Eurojust) that dismantled a ransomware affiliate group linked to LockerGoga, MegaCortex, Hive and Dharma deployments; Ukrainian authorities also reported seizing more than $600,000 in cryptocurrency, nine vehicles and 24 plots of land in connection with the case.

OPERATIONAL PATTERN (PER DOJ) Between March 2019 and about June 2020, Vardanyan and co-conspirators illegally accessed computer networks of victim companies, deployed Ryuk ransomware on compromised servers and workstations, and placed ransom notes on infected systems demanding payment in cryptocurrency (typically Bitcoin), with an email address provided for victims to contact the attackers. Victims included companies, schools, hospitals, municipalities and other entities worldwide. Identified victims include a Michigan company that paid approximately 200 bitcoins (more than $1.1 million at the time) in January 2020, a technology company in Wilsonville, Oregon attacked in December 2019, and a Texas school breached in February 2020. DOJ stated the conspirators received approximately 1,610 bitcoins in ransom payments, valued at over $15 million at the time of payment (some secondary reporting, including the hunt source, cites 1,160 BTC; the DOJ figure quoted by BleepingComputer and Bitdefender is 1,610). Reporting also notes the charged activity window is cited variously as March 2019-June 2020 (DOJ) and November 2019-April 2020 (specific victim attacks).

RYUK TRADECRAFT CONTEXT Ryuk was first detected in August 2018, is attributed by MITRE ATT&CK (S0446) to Wizard Spider, and was later succeeded by Conti. Ryuk operations peaked in 2020 with heavy targeting of healthcare during the COVID-19 pandemic (Universal Health Services reported a $67 million loss). CISA/FBI/HHS advisory AA20-302A (October 2020) documents contemporaneous Ryuk intrusion tradecraft: initial infection via TrickBot or BazarLoader (phishing emails linking to Google Drive-hosted payloads such as Report-Review26-10.exe and Document_Print.exe); post-exploitation with Cobalt Strike and PowerShell Empire; credential dumping with Mimikatz; reconnaissance with net view, AdFind and BloodHound; lateral movement over RDP, WMI, WinRM and PowerShell; persistence via scheduled tasks and the HKCU Run key; termination of security tools; deletion of shadow copies with 'vssadmin Delete Shadows /all /quiet'; and AES-256/RSA encryption appending the .RYK extension with a RyukReadMe.txt ransom note containing ProtonMail contact addresses and a Bitcoin wallet. MITRE additionally documents Ryuk's use of stolen domain administrator accounts, the C$ admin share, remote scheduled tasks, icacls permission resets, process injection, SeDebugPrivilege token adjustment, Wake-on-LAN, and a system-language check that halts on Russian, Ukrainian or Belarusian locales.

DEFENDER SIGNIFICANCE This is a law-enforcement outcome for a historical (2019-2020) Ryuk campaign; the court filings released publicly contain no CVEs or new technical IOCs. Its value is attribution enrichment (named operator, monikers, co-defendants, victim profile, and the initial-access-specialist role in the ransomware supply chain) for existing Ryuk/TrickBot/BazarLoader coverage. Network indicators listed in this record are the TrickBot/Ryuk-ecosystem indicators published in CISA AA20-302A for the same era; BeaconBeagle returned no current beacon records for sampled IPs, so they should be treated as historical and low-fidelity for live blocking.

MITRE ATT&CK techniques used in TL-2026-2634

Credential Access

T1003.001 OS Credential Dumping: LSASS Memory

Discovery

T1018 Remote System Discovery; T1087.002 Account Discovery: Domain Account; T1614.001 System Location Discovery: System Language Discovery

Lateral Movement

T1021.001 Remote Services: Remote Desktop Protocol; T1021.002 Remote Services: SMB/Windows Admin Shares

Execution

T1047 Windows Management Instrumentation; T1059.001 Command and Scripting Interpreter: PowerShell; T1059.003 Command and Scripting Interpreter: Windows Command Shell

Persistence

T1053.005 Scheduled Task/Job: Scheduled Task; T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder

Privilege Escalation

T1055 Process Injection; T1134 Access Token Manipulation

Initial Access

T1078.002 Valid Accounts: Domain Accounts; T1566.002 Phishing: Spearphishing Link

Defense Impairment

T1222.001 Windows Permissions; T1685 Disable or Modify Tools

Impact

T1489 Service Stop; T1490 Inhibit System Recovery; T1657 Financial Theft

Reconnaissance

T1595.002 Active Scanning: Vulnerability Scanning

Affected products and versions in Ryuk Ransomware Initial Access Operator Karen Vardanyan

  • Microsoft — Windows (servers and workstations in victim enterprise networks)
    Vulnerable versions: All Windows versions targeted by Ryuk ransomware

Remediation for Ryuk Ransomware Initial Access Operator Karen Vardanyan

Immediate actions

  • Hunt historical telemetry for Ryuk-era artifacts: files with the .RYK extension, RyukReadMe.txt ransom notes, 'vssadmin Delete Shadows /all /quiet' executions and kill.bat-style service-stop scripts
  • Review retained network logs for connections to the TrickBot/Ryuk-ecosystem infrastructure published in CISA AA20-302A (treat as historical, low-fidelity indicators)
  • Audit externally exposed remote-access services (RDP, VPN) for unexpected successful authentications, since this operator specialised in brokering initial network access
  • Victims of the 2019-2020 Ryuk campaign should coordinate with the FBI Portland Field Office regarding restitution

Workarounds

  • Disable or restrict Wake-on-LAN where not operationally required
  • Apply least-privilege ACLs to backup repositories and monitor for mass icacls permission resets

Longer-term hardening

  • Enforce MFA on all remote access and privileged accounts to blunt initial-access brokers and stolen domain-admin credential abuse
  • Deploy EDR with tamper protection to detect and block security-tool termination and shadow-copy deletion
  • Maintain offline, immutable backups tested for restoration to reduce leverage of ransomware extortion
  • Block and alert on phishing delivery chains used by TrickBot/BazarLoader loaders (links to cloud-hosted executables)
  • Restrict administrative shares (C$), WMI and WinRM lateral movement with host firewall policy and tiered administration
  • Monitor for Mimikatz-style LSASS access and for AdFind/BloodHound Active Directory enumeration

Timeline of Ryuk Ransomware Initial Access Operator Karen Vardanyan

  • Ryuk ransomware first detected in the wild (August 2018); later linked to the TrickBot-operating Wizard Spider ecosystem and succeeded by Conti.
  • Start of the charged conspiracy period (March 2019) in which Vardanyan and co-conspirators illegally accessed victim networks and deployed Ryuk on compromised servers and workstations.
  • Ryuk attack against a technology company in Wilsonville, Oregon (December 2019), the victim that gave the District of Oregon jurisdiction.
  • A Michigan company paid approximately 200 bitcoins (more than $1.1 million at the time) in ransom after a Ryuk attack (January 2020).
  • Texas school breached and targeted with Ryuk ransomware (February 2020).
  • End of the charged conspiracy period (about June 2020); DOJ says the conspirators received roughly 1,610 bitcoins in ransom (over $15 million at time of payment).
  • CISA, FBI and HHS publish joint advisory AA20-302A on TrickBot, BazarLoader and Ryuk activity targeting the healthcare sector, including Ryuk TTPs and TrickBot C2 indicators.
  • Multinational raid in Ukraine (30 properties searched, ringleader and four accomplices detained) dismantles a ransomware affiliate group; forensic analysis of seized equipment later identifies Vardanyan.
  • Federal grand jury in Portland returns superseding indictment charging Vardanyan, Avetisyan, Lyulyava and Prykhodchenko with conspiracy, computer fraud and computer extortion.
  • Vardanyan arrested at his home in Kyiv, Ukraine (April 2025) at the request of the FBI; Ukrainian authorities seize over $600,000 in cryptocurrency, nine vehicles and 24 plots of land.
  • Vardanyan extradited from Ukraine to the United States.
  • Vardanyan makes initial appearance in U.S. federal court in Portland, Oregon.
  • Vardanyan pleads guilty to conspiracy and fraud in connection with computers (statutory maximum 15 years).
  • Vardanyan sentenced to 24 months in federal prison, 3 years supervised release and $1,219,106 restitution; faces removal from the U.S. after release.

Sources cited for Ryuk Ransomware Initial Access Operator Karen Vardanyan

More in ransomware

Detection coverage for TL-2026-2634

As of 2026-09-23, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2634 across Splunk SPL, Microsoft KQL and Sigma, covering 29 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats