Ryuk Ransomware Initial Access Operator Karen Vardanyan ("Maneeken") Sentenced to 24 Months in U.S. Federal Prison
Ryuk Ransomware Initial Access Operator Karen Vardanyan (TL-2026-2634), also tracked as Ryuk, is a medium-severity ransomware operation, first published 2026-09-23. It is attributed to Karen Vardanyan with high confidence, affects Microsoft Windows (servers and workstations in victim enterprise, maps to 21 MITRE ATT&CK techniques (T1003.001, T1018, T1021.001), and is covered by 9 detection rules and 29 indicators of compromise.
Key facts for TL-2026-2634
- Threat ID
- TL-2026-2634
- Also known as
- Ryuk, United States v. Vardanyan (D. Or.)
- Severity
- MEDIUM
- Status
- TRACKING
- Category
- RANSOMWARE
- First published
- 2026-09-23
- Last reviewed
- 2026-09-23
- Attribution
- Karen Vardanyan
- Attribution confidence
- HIGH
- Motivation
- FINANCIAL
- Target sectors
- technology, manufacturing, education, health, government administration, municipalities, enterprise
- Target regions
- North America, united states of america, Global
- Detection rules
- 9
- Indicators of compromise
- 29
Malware and tooling in Ryuk Ransomware Initial Access Operator Karen Vardanyan
Malware and tooling: BazarBackdoor, Cobalt Strike, Conti, LockerGoga, MegaCortex, MimiKatz, Ryuk, Ryuk ransomware, TrickBot, AdFind - S0552, BloodHound - S0521, Cobalt Strike
Karen Serobovich Vardanyan, a 35-year-old Armenian national extradited from Ukraine, was sentenced on September 22, 2026 in the U.S. District Court for the District of Oregon to 24 months in prison, 3 years of supervised release and $1,219,106 in restitution for his role in a Ryuk ransomware conspiracy active from March 2019 to about June 2020. Vardanyan, who operated as an initial access specialist under the monikers "Maneeken" and "Karl Lagerfeld", illegally accessed victim networks and helped deploy Ryuk on compromised servers and workstations; three co-defendants (Levon Avetisyan, Oleg Lyulyava, Andrii Prykhodchenko) remain charged.
How Ryuk Ransomware Initial Access Operator Karen Vardanyan works
OVERVIEW On September 22, 2026, U.S. Attorney Scott E. Bradford for the District of Oregon announced that Karen Serobovich Vardanyan, 35, an Armenian national, was sentenced to 24 months in federal prison followed by 3 years of supervised release and ordered to pay $1,219,106.00 in restitution to victims. Vardanyan will face removal from the United States after serving his sentence. On July 8, 2026 he pleaded guilty to conspiracy and fraud in connection with computers; the plea carried a statutory maximum of 15 years. The case was investigated by the FBI and prosecuted by Assistant U.S. Attorney Katherine Rykken, with the Justice Department's Office of International Affairs securing extradition and Ukrainian authorities providing assistance.
CHARGES AND PROCEDURAL HISTORY A federal grand jury in Portland returned a superseding indictment on February 22, 2024 charging Vardanyan and co-conspirators with conspiracy, fraud in connection with computers, and extortion in connection with computers. Co-defendants named in the indictment are Levon Georgiyovych Avetisyan (45, Armenian national) and Oleg Nikolayevich Lyulyava and Andrii Leonydovich Prykhodchenko (both 53, Ukrainian nationals). Vardanyan was arrested at his home in Kyiv in April 2025 at the request of the FBI (Ukraine's Office of the Prosecutor General described him as an initial access specialist who searched for vulnerabilities in corporate networks and passed the access to accomplices who then carried out the attacks), was extradited on June 18, 2025, and made his initial appearance in Portland federal court on June 20, 2025. Ukrainian authorities reported that he was identified through forensic analysis of equipment seized in the November 21, 2023 multinational raid in Ukraine (Ukrainian National Police with investigators from Norway, France, Germany and the United States, supported by Europol and Eurojust) that dismantled a ransomware affiliate group linked to LockerGoga, MegaCortex, Hive and Dharma deployments; Ukrainian authorities also reported seizing more than $600,000 in cryptocurrency, nine vehicles and 24 plots of land in connection with the case.
OPERATIONAL PATTERN (PER DOJ) Between March 2019 and about June 2020, Vardanyan and co-conspirators illegally accessed computer networks of victim companies, deployed Ryuk ransomware on compromised servers and workstations, and placed ransom notes on infected systems demanding payment in cryptocurrency (typically Bitcoin), with an email address provided for victims to contact the attackers. Victims included companies, schools, hospitals, municipalities and other entities worldwide. Identified victims include a Michigan company that paid approximately 200 bitcoins (more than $1.1 million at the time) in January 2020, a technology company in Wilsonville, Oregon attacked in December 2019, and a Texas school breached in February 2020. DOJ stated the conspirators received approximately 1,610 bitcoins in ransom payments, valued at over $15 million at the time of payment (some secondary reporting, including the hunt source, cites 1,160 BTC; the DOJ figure quoted by BleepingComputer and Bitdefender is 1,610). Reporting also notes the charged activity window is cited variously as March 2019-June 2020 (DOJ) and November 2019-April 2020 (specific victim attacks).
RYUK TRADECRAFT CONTEXT Ryuk was first detected in August 2018, is attributed by MITRE ATT&CK (S0446) to Wizard Spider, and was later succeeded by Conti. Ryuk operations peaked in 2020 with heavy targeting of healthcare during the COVID-19 pandemic (Universal Health Services reported a $67 million loss). CISA/FBI/HHS advisory AA20-302A (October 2020) documents contemporaneous Ryuk intrusion tradecraft: initial infection via TrickBot or BazarLoader (phishing emails linking to Google Drive-hosted payloads such as Report-Review26-10.exe and Document_Print.exe); post-exploitation with Cobalt Strike and PowerShell Empire; credential dumping with Mimikatz; reconnaissance with net view, AdFind and BloodHound; lateral movement over RDP, WMI, WinRM and PowerShell; persistence via scheduled tasks and the HKCU Run key; termination of security tools; deletion of shadow copies with 'vssadmin Delete Shadows /all /quiet'; and AES-256/RSA encryption appending the .RYK extension with a RyukReadMe.txt ransom note containing ProtonMail contact addresses and a Bitcoin wallet. MITRE additionally documents Ryuk's use of stolen domain administrator accounts, the C$ admin share, remote scheduled tasks, icacls permission resets, process injection, SeDebugPrivilege token adjustment, Wake-on-LAN, and a system-language check that halts on Russian, Ukrainian or Belarusian locales.
DEFENDER SIGNIFICANCE This is a law-enforcement outcome for a historical (2019-2020) Ryuk campaign; the court filings released publicly contain no CVEs or new technical IOCs. Its value is attribution enrichment (named operator, monikers, co-defendants, victim profile, and the initial-access-specialist role in the ransomware supply chain) for existing Ryuk/TrickBot/BazarLoader coverage. Network indicators listed in this record are the TrickBot/Ryuk-ecosystem indicators published in CISA AA20-302A for the same era; BeaconBeagle returned no current beacon records for sampled IPs, so they should be treated as historical and low-fidelity for live blocking.
MITRE ATT&CK techniques used in TL-2026-2634
Credential Access
T1003.001 OS Credential Dumping: LSASS Memory
Discovery
T1018 Remote System Discovery; T1087.002 Account Discovery: Domain Account; T1614.001 System Location Discovery: System Language Discovery
Lateral Movement
T1021.001 Remote Services: Remote Desktop Protocol; T1021.002 Remote Services: SMB/Windows Admin Shares
Execution
T1047 Windows Management Instrumentation; T1059.001 Command and Scripting Interpreter: PowerShell; T1059.003 Command and Scripting Interpreter: Windows Command Shell
Persistence
T1053.005 Scheduled Task/Job: Scheduled Task; T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
Privilege Escalation
T1055 Process Injection; T1134 Access Token Manipulation
Initial Access
T1078.002 Valid Accounts: Domain Accounts; T1566.002 Phishing: Spearphishing Link
Defense Impairment
T1222.001 Windows Permissions; T1685 Disable or Modify Tools
Impact
T1489 Service Stop; T1490 Inhibit System Recovery; T1657 Financial Theft
Reconnaissance
Affected products and versions in Ryuk Ransomware Initial Access Operator Karen Vardanyan
- Microsoft — Windows (servers and workstations in victim enterprise networks)
Vulnerable versions: All Windows versions targeted by Ryuk ransomware
Remediation for Ryuk Ransomware Initial Access Operator Karen Vardanyan
Immediate actions
- Hunt historical telemetry for Ryuk-era artifacts: files with the .RYK extension, RyukReadMe.txt ransom notes, 'vssadmin Delete Shadows /all /quiet' executions and kill.bat-style service-stop scripts
- Review retained network logs for connections to the TrickBot/Ryuk-ecosystem infrastructure published in CISA AA20-302A (treat as historical, low-fidelity indicators)
- Audit externally exposed remote-access services (RDP, VPN) for unexpected successful authentications, since this operator specialised in brokering initial network access
- Victims of the 2019-2020 Ryuk campaign should coordinate with the FBI Portland Field Office regarding restitution
Workarounds
- Disable or restrict Wake-on-LAN where not operationally required
- Apply least-privilege ACLs to backup repositories and monitor for mass icacls permission resets
Longer-term hardening
- Enforce MFA on all remote access and privileged accounts to blunt initial-access brokers and stolen domain-admin credential abuse
- Deploy EDR with tamper protection to detect and block security-tool termination and shadow-copy deletion
- Maintain offline, immutable backups tested for restoration to reduce leverage of ransomware extortion
- Block and alert on phishing delivery chains used by TrickBot/BazarLoader loaders (links to cloud-hosted executables)
- Restrict administrative shares (C$), WMI and WinRM lateral movement with host firewall policy and tiered administration
- Monitor for Mimikatz-style LSASS access and for AdFind/BloodHound Active Directory enumeration
Timeline of Ryuk Ransomware Initial Access Operator Karen Vardanyan
- Ryuk ransomware first detected in the wild (August 2018); later linked to the TrickBot-operating Wizard Spider ecosystem and succeeded by Conti.
- Start of the charged conspiracy period (March 2019) in which Vardanyan and co-conspirators illegally accessed victim networks and deployed Ryuk on compromised servers and workstations.
- Ryuk attack against a technology company in Wilsonville, Oregon (December 2019), the victim that gave the District of Oregon jurisdiction.
- A Michigan company paid approximately 200 bitcoins (more than $1.1 million at the time) in ransom after a Ryuk attack (January 2020).
- Texas school breached and targeted with Ryuk ransomware (February 2020).
- End of the charged conspiracy period (about June 2020); DOJ says the conspirators received roughly 1,610 bitcoins in ransom (over $15 million at time of payment).
- CISA, FBI and HHS publish joint advisory AA20-302A on TrickBot, BazarLoader and Ryuk activity targeting the healthcare sector, including Ryuk TTPs and TrickBot C2 indicators.
- Multinational raid in Ukraine (30 properties searched, ringleader and four accomplices detained) dismantles a ransomware affiliate group; forensic analysis of seized equipment later identifies Vardanyan.
- Federal grand jury in Portland returns superseding indictment charging Vardanyan, Avetisyan, Lyulyava and Prykhodchenko with conspiracy, computer fraud and computer extortion.
- Vardanyan arrested at his home in Kyiv, Ukraine (April 2025) at the request of the FBI; Ukrainian authorities seize over $600,000 in cryptocurrency, nine vehicles and 24 plots of land.
- Vardanyan extradited from Ukraine to the United States.
- Vardanyan makes initial appearance in U.S. federal court in Portland, Oregon.
- Vardanyan pleads guilty to conspiracy and fraud in connection with computers (statutory maximum 15 years).
- Vardanyan sentenced to 24 months in federal prison, 3 years supervised release and $1,219,106 restitution; faces removal from the U.S. after release.
Sources cited for Ryuk Ransomware Initial Access Operator Karen Vardanyan
- Ryuk ransomware operator sentenced to 2 years in prison (CyberScoop)
- District of Oregon | Armenian National Extradited to the United States Sentenced to Federal Prison for Ransomware Extortion Scheme
- District of Oregon | Armenian National Extradited to the United States Pleads Guilty to Ransomware Extortion Conspiracy
- Armenian National Extradited to the United States Faces Federal Charges for Ransomware Extortion Conspiracy (FBI Portland)
- Armenian National Sentenced for Ransomware Extortion Scheme (Gorge News Center, DOJ release reprint)
- Ryuk ransomware member sentenced to 24 months in prison (BleepingComputer)
- Ryuk ransomware operator gets 2-year sentence after extorting victims for $1.2 million (The Record)
- Up to 15 years in prison for alleged Ryuk ransomware member (Bitdefender HotForSecurity)
- Alleged Ryuk ransomware gang member arrested in Ukraine and extradited to US (The Record)
- Alleged Ryuk Initial Access Broker Extradited to the US (Infosecurity Magazine)
- International collaboration leads to dismantlement of ransomware group in Ukraine amidst ongoing war (Europol)
- CISA AA20-302A: Ransomware Activity Targeting the Healthcare and Public Health Sector (TrickBot, BazarLoader, Ryuk)
- MITRE ATT&CK Software S0446: Ryuk
More in ransomware
- BlueLocker Ransomware Resurfaces After Three-Year Dormancy, Breaches Pakistan Petroleum Limited
- Storm-3168 (JADEPUFFER): Agentic-Driven Destructive Cloud Attacks Against Azure via Compromised Service Principals
- Vexy Ransomware Claims Data-Extortion Attack on Majani Insurance Brokers (Kenya)
- Vexy Ransomware Claims Quy Nhon University (Vietnam) — New Group, 50GB Exfiltrated
- Ransomware Attack Disrupts IT Systems and Services in Ellis County, Kansas
Detection coverage for TL-2026-2634
As of 2026-09-23, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2634 across Splunk SPL, Microsoft KQL and Sigma, covering 29 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.