Executive Summary
Karen Serobovich Vardanyan, a 35-year-old Armenian national known online as 'Maneeken' or 'Karl Lagerfeld,' was sentenced to 24 months in prison for his role in Ryuk ransomware attacks between March 2019 and June 2020. Vardanyan specialized in gaining initial access to corporate networks, helping his cybercriminal group breach multiple U.S. organizations including companies in Michigan, Texas, and Oregon. The group collected over $15 million in ransom payments, with one Michigan company alone paying 200 BTC worth over $1.1 million. Vardanyan was extradited from Ukraine in 2025 and pleaded guilty in July 2026.
This sentencing highlights the ongoing global law enforcement efforts to prosecute ransomware operators, even years after attacks occurred. As ransomware groups continue to evolve and fragment into smaller units, the Ryuk-to-Conti evolution demonstrates how cybercriminal organizations adapt and rebrand while maintaining similar attack methodologies.
Why This Matters Now
Ransomware attacks have surged 41% in 2024, with threat actors increasingly targeting critical infrastructure. This prosecution demonstrates that law enforcement can successfully track and prosecute ransomware operators across international borders, serving as a deterrent while highlighting the persistent threat these organized criminal groups pose to organizations worldwide.
Attack Path Analysis
Ryuk ransomware operators gained initial access through compromised credentials or phishing attacks, escalated privileges through local system compromise, moved laterally across corporate networks to identify high-value targets, maintained command and control channels for coordination, exfiltrated sensitive data for double extortion, and deployed ransomware across hundreds of servers and workstations causing widespread business disruption.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers gained initial access to corporate networks through compromised credentials, phishing emails, or exploitation of internet-facing services
MITRE ATT&CK® Techniques
Valid Accounts
Exploit Public-Facing Application
Exploitation of Remote Services
Data Encrypted for Impact
Inhibit System Recovery
Service Stop
Remote System Discovery
File and Directory Discovery
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Network Segmentation and Monitoring
Control ID: 11.3.1
NYDFS 23 NYCRR 500 – Incident Response Plan
Control ID: 500.15
DORA – ICT Risk Management Framework
Control ID: Article 11
CISA ZTMM 2.0 – Identity Verification and Access Control
Control ID: Identity Domain
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
ISO 27001 – Information Backup
Control ID: A.12.3.1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Health Care / Life Sciences
Ryuk ransomware specifically targeted healthcare during COVID-19, exploiting lateral movement vulnerabilities and encrypting critical patient systems requiring enhanced segmentation controls.
Higher Education/Acadamia
Texas school breach demonstrates education sector vulnerability to Ryuk's initial access techniques, necessitating zero trust segmentation and egress security controls.
Information Technology/IT
Oregon technology company breach highlights IT sector exposure to ransomware exfiltration attacks, requiring encrypted traffic protection and multicloud visibility capabilities.
Financial Services
Multi-million dollar Bitcoin ransom payments expose financial institutions to cryptocurrency-based extortion requiring enhanced threat detection and anomaly response systems.
Sources
- Ryuk ransomware member sentenced to 24 months in prisonhttps://www.bleepingcomputer.com/news/security/ryuk-ransomware-member-sentenced-to-24-months-in-prison/Verified
- Armenian National Extradited to United States Pleads Guilty to Ransomware Extortion Conspiracyhttps://www.justice.gov/usao-or/pr/armenian-national-extradited-united-states-pleads-guilty-ransomware-extortion-conspiracyVerified
- Ryuk Ransomware Analysis and Threat Intelligencehttps://attack.mitre.org/software/S0446/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would have significantly constrained the Ryuk ransomware operators' ability to move laterally and deploy encryption across hundreds of systems. The segmented cloud fabric architecture would likely have reduced the attack's blast radius and limited cross-network propagation.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The cloud native security fabric would likely have limited the compromised credentials' effective reach across cloud workloads and constrained initial access to segmented network zones rather than allowing broad network visibility
Control: Zero Trust Segmentation
Mitigation: Zero trust segmentation policies would likely have constrained privilege escalation attempts by limiting administrative access paths between network segments and reducing the scope of systems accessible for credential harvesting
Control: East-West Traffic Security
Mitigation: East-west traffic security controls would likely have significantly constrained lateral movement by blocking unauthorized inter-segment communications and limiting attackers' ability to traverse between workload environments using stolen credentials
Control: Multicloud Visibility & Control
Mitigation: Multicloud visibility and control capabilities would likely have detected and constrained command and control communications across different cloud environments, limiting the attackers' coordination capabilities between victim organizations
Control: Egress Security & Policy Enforcement
Mitigation: Egress security policies would likely have constrained large-scale data exfiltration by blocking unauthorized outbound transfers and limiting attackers' ability to extract sensitive information for double extortion tactics
While ransomware deployment might still occur within compromised segments, the blast radius would likely have been significantly reduced to isolated workload groups rather than hundreds of systems across the entire infrastructure
Impact at a Glance
Affected Business Functions
- Data Processing Systems
- Financial Operations
- IT Infrastructure
- Educational Services
Estimated downtime: 14 days
Estimated loss: $15,000,000
Corporate networks of multiple organizations including a Michigan company, Texas school district, and Oregon technology firm were compromised. Sensitive business data and systems were encrypted and held for ransom, with total ransom payments exceeding $15 million across all victims.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation with identity-based policies and microsegmentation to prevent lateral movement across corporate networks
- • Deploy East-West Traffic Security controls to detect and block unauthorized workload-to-workload communications during lateral movement phases
- • Enable Egress Security & Policy Enforcement to prevent data exfiltration and block unauthorized outbound connections to attacker infrastructure
- • Establish Multicloud Visibility & Control with centralized policy management to detect anomalous interactions and suspicious automation across hybrid environments
- • Deploy Threat Detection & Anomaly Response capabilities with behavioral baselining to identify covert tools and unauthorized remote access attempts



