Ryuk Ransomware Member Jailed for 24 Months

Karen Serobovich Vardanyan faces prison time for stealing over $15 million in Bitcoin from US firms between 2019 and 2020.
Key points
- Karen Serobovich Vardanyan was sentenced to 24 months in prison and three years of supervised release.
- The Ryuk group stole over $15 million in Bitcoin from U.S. victims between 2019 and 2020.
- Vardanyan was extradited from Ukraine after being arrested in April 2025.
An Armenian national has been sentenced to two years in federal prison for his role in one of the most lucrative ransomware operations of the late 2010s. Karen Serobovich Vardanyan, who operated under the handle Maneeken, pleaded guilty to hacking multiple U.S. organizations and deploying encryption software that paralyzed their systems.
The sentence includes three years of supervised release following his incarceration. Vardanyan was extradited from Ukraine to the United States after being arrested in April 2025. Prosecutors identified him as a specialist in gaining initial access to corporate networks, a critical step in the multi-stage ransomware attacks his group conducted.
Financial gains from corporate breaches
According to court documents, Vardanyan and his accomplices targeted U.S. companies between March 2019 and June 2020. In one notable incident, a Michigan-based company paid a ransom of 200 bitcoins, which was worth over $1.1 million at the time. Other victims included a school in Texas and a technology firm in Oregon, illustrating the breadth of the group's targets.
The U.S. Department of Justice stated that the group received approximately 1,610 bitcoins in total ransom payments. This amount was valued at over $15 million when the transactions occurred. The operation involved compromising hundreds of servers and workstations, forcing victims to pay to regain access to their own data.
Ryuk's peak and eventual shutdown
Ryuk was a ransomware-as-a-service operation that ran from August 2018 until mid-2020. It gained notoriety for a massive wave of attacks on the healthcare sector during the early stages of the pandemic. At its height, the group compromised around 20 victims per week, collecting more than $150 million in ransoms.
As reported by BleepingComputer, the group behind Ryuk, known as Wizard Spider, eventually disbanded. Following the shutdown, its members switched to Conti ransomware, which became one of the most prolific hacker groups. However, Conti also collapsed in 2022 after a leak of its internal chats and source code, leading to a fragmentation of its members into smaller units.
Implications for corporate security
The sentencing highlights the persistent threat posed by organized cybercrime groups that monetize initial access. For businesses, the stakes are clear: a single successful breach can result in multi-million dollar losses and operational downtime. The case underscores the need for robust network segmentation and rapid response capabilities to limit the blast radius of ransomware deployments.






