Ryuk Operator Sentenced as U.S. Case Exposes the Ransomware Group’s Global Reach

Ryuk member Karen Vardanyan sentenced to 2 years in U.S. for 2,400 ransomware attacks collecting $15M from hospitals, firms.

Ryuk Operator Sentenced as U.S. Case Exposes the Ransomware Group’s Global Reach
Ransomware

Illustrative image generated with AI

Listen to this articleAudio edition · 9 min

Karen Vardanyan, a 35-year-old Armenian national described by U.S. prosecutors as a core Ryuk ransomware member, has received a two-year federal prison sentence.

Vardanyan pleaded guilty in July to conspiracy and computer-related fraud charges. After completing his prison term, he will remain under supervised release for three years and must pay $1,219,106 in restitution to victims.

The sentence addresses only one participant in a much larger operation. Court filings attributed more than 2,400 ransomware attacks worldwide to Vardanyan and his co-conspirators, with at least $15 million collected in ransom payments.

Extradition brought a wanted operator into U.S. custody

Vardanyan was extradited from Ukraine in July 2025 following his arrest in Kyiv. Before that arrest, he had been placed on an FBI international wanted list.

Prosecutors said he personally conducted multiple ransomware operations and extorted more than $1 million from victims. The precise relationship between that figure and the $1,219,106 restitution order has not been publicly detailed, so the two amounts should not be treated as interchangeable.

The U.S. prosecution of Vardanyan reflects the international scope of the investigation. An Armenian national arrested in Ukraine was ultimately transferred to the United States to face charges tied to victims across multiple jurisdictions.

The two-year term is accompanied by financial and post-release penalties, but it remains substantially smaller than the overall damage attributed to the group. Ryuk’s operators collected at least $15 million, while individual incidents generated costs far beyond the ransom itself.

More than 2,400 attacks disrupted essential operations

Ryuk attacks affected private companies, healthcare organizations, municipalities, and other public-sector entities. State and local government bodies were among the confirmed victims.

According to prosecutors, the intrusions materially impaired targeted organizations. Ryuk denied access to data and disrupted communications and other operational functions, creating consequences that extended beyond affected computers.

That distinction is critical for hospitals and government agencies. When ransomware disables communications or makes operational records unavailable, the incident can interfere with public services and healthcare delivery rather than merely producing an information technology outage.

Universal Health Services provides the clearest financial example. The hospital chain suffered a Ryuk incident that ultimately resulted in $67 million in costs. That amount illustrates how recovery expenses, operational disruption, investigation, system restoration, and lost business can greatly exceed any ransom demand.

During the COVID-19 pandemic in 2020, the FBI and other U.S. agencies warned that Ryuk operators were aggressively targeting hospitals across the United States. Healthcare organizations were already operating under severe pressure, increasing the potential impact of outages affecting clinical and administrative systems.

Municipalities faced a related risk. Local governments often depend on interconnected systems for communications, public administration, and service delivery, allowing a ransomware incident to spread operational consequences across multiple departments.

Ryuk’s technical impact centered on data denial and disruption

Ryuk was first detected in August 2018 and has previously been associated with Russian cybercriminals. Security researchers also connected the ransomware organization to a Russian group operating the TrickBot malware.

That association places Ryuk within a broader criminal ecosystem rather than treating it as an isolated encryption tool. Such ecosystems can separate malware operation, intrusion activity, extortion, payment handling, and money laundering among different participants.

However, the public case details do not identify the initial-access techniques used in Vardanyan’s specific attacks. They also do not provide information about exploited vulnerabilities, encryption methods, command-and-control infrastructure, file extensions, ransom-note names, or other technical indicators.

No affected software versions or security patches are relevant to the case as described. This was a criminal prosecution involving ransomware operations, not the disclosure of a product vulnerability. There is therefore no associated CVE or CISA Known Exploited Vulnerabilities catalog entry.

The documented technical outcome was nevertheless clear: victims lost access to data, communications were interrupted, and essential functions were degraded. For defenders, those effects matter more than the ransomware brand alone because similar operational patterns can be produced by other extortion groups.

Investigators targeted both operators and payment infrastructure

U.S. officials did not limit their efforts to the systems used for encryption. Authorities also dismantled Ryuk’s money-laundering operations, attacking the financial infrastructure required to convert ransom payments into usable proceeds.

The broader investigation identified several other alleged members. They included Armenian national Levon Georgiyovych Avetisyan and two 53-year-old Ukrainian nationals, Oleg Nikolayevich Lyulyava and Andrii Leonydovich Prykhodchenko.

In 2023, a Russian national pleaded guilty in an Oregon federal court to laundering Ryuk proceeds over a three-year period. He was accused of acting as a financial intermediary for the organization alongside 13 unnamed co-conspirators.

These cases reveal a division of labor within the ransomware network. Intruders and ransomware operators could impair victims and negotiate payments, while separate participants handled the movement and laundering of the resulting funds.

Disrupting that financial layer can make an operation harder to sustain even when every technical participant has not been arrested. Extradition and prosecution also increase the risk for members who travel or operate from countries willing to cooperate with U.S. authorities.

Hospitals and municipalities should prepare for operational failure

No case-specific indicators of compromise, recovery procedure, or technical workaround have been disclosed. Organizations cannot use this prosecution as a source of hashes, network addresses, detection signatures, or patch guidance.

They can, however, prepare for the operational conditions documented across the Ryuk attacks:

  • Maintain offline or otherwise isolated backups and regularly test whether critical systems can be restored.
  • Restrict privileged access so that a compromised account cannot easily reach every administrative system or backup repository.
  • Monitor for lateral movement, unusual administrative activity, mass file access, and ransomware staging.
  • Separate critical communications and operational services from general-purpose corporate networks where feasible.
  • Develop response procedures for situations in which normal email, identity, or endpoint-management systems become unavailable.
  • Coordinate incident-response plans with law enforcement before an attack occurs, particularly in healthcare and local government environments.

Backups alone are not sufficient if attackers can delete them, encrypt them, or compromise the credentials used to manage them. Recovery exercises should therefore test identity systems, communications, dependencies, and the order in which essential services must return.

Vardanyan’s conviction removes one alleged core participant and imposes restitution for victim losses. It does not eliminate the wider ransomware model demonstrated by Ryuk: internationally distributed operators, high-impact disruption, and specialized infrastructure for turning attacks into revenue.

Read next

Sources

This article is an original reworking based on the sources below.

Related topicsRyuk ransomwareKaren Vardanyanransomware sentencinghealthcare cyberattackFBI extraditionransomware money laundering
Back to home