Armenian national Karen Serobovich Vardanyan, also known as “Maneeken” and “Karl Lagerfeld,” was sentenced to 24 months in U.S. federal prison for his role in the Ryuk ransomware conspiracy. Extradited from Ukraine in 2025, Vardanyan pleaded guilty in July 2026 to conspiracy and computer fraud; his sentence also includes three years of supervised release and $1,219,106 in victim restitution.
Vardanyan obtained initial access to corporate networks used in Ryuk attacks against organizations worldwide from March 2019 through about June 2020, including victims in Michigan, Texas, and Oregon. The group encrypted victim systems and demanded Bitcoin payments for restoration, receiving roughly 1,610 BTC—valued at more than $15 million at the time—from hundreds of compromised systems; the FBI, Ukrainian authorities, and the U.S. Justice Department supported the investigation and prosecution.

TTPs, infrastructure, and targeting history in one profile.
8 events from the most recent confirmed update back to the earliest known activity.
Vardanyan pleaded guilty to conspiracy and computer fraud for his role in the Ryuk ransomware conspiracy.
Ukraine extradited Vardanyan to the United States, where he made his initial appearance in federal court and was ordered detained by a magistrate judge.
Ukrainian authorities arrested Armenian national Karen Vardanyan in Kyiv in connection with his alleged role in Ryuk ransomware attacks.
A federal grand jury in Portland returned a superseding indictment charging Vardanyan with conspiracy, computer fraud, and computer extortion related to the Ryuk ransomware scheme.
The Ryuk operation shut down in 2020, after which Wizard Spider shifted to operating the Conti ransomware operation.
Karen Serobovich Vardanyan and co-conspirators conducted Ryuk ransomware attacks from March 2019 through approximately June 2020, gaining unauthorized access and deploying ransomware on hundreds of systems. Victims included a Michigan company, a Texas school, and a technology company in Wilsonville, Oregon; the conspirators received roughly 1,610 BTC, valued at more than $15 million when paid.
The Wizard Spider cybercrime gang operated Ryuk as a ransomware-as-a-service operation beginning in August 2018. The operation later became associated with attacks on healthcare organizations during the COVID-19 pandemic.
A U.S. court sentenced Vardanyan to 24 months in federal prison and three years of supervised release for his Ryuk ransomware role. The court also ordered him to pay $1,219,106 in restitution to victims.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
4 references tracked. Mallory keeps watching after this page renders.
databreaches.net
Open sourcetherecord.media
Open sourcecybersecuritynews.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.