The Good, the Bad and the Ugly in Cybersecurity – Week 39 (2026)
Cybersecurity Classified by Officially
The Good | U.S. Court Sentences Initial Access Specialist Tied to Ryuk Ransomware
A court has sentenced Armenian citizen Karen Serobovich Vardanyan to two years in federal prison and three years of supervised release for his role in launching high-profile Ryuk ransomware attacks against corporate networks throughout the United States. Vardanyan, also known online as ‘Maneeken’ or ‘Karl Lagerfeld’, was originally extradited to Oregon from Kyiv, Ukraine, in a coordinated effort between international law enforcement authorities.
In addition to his custodial sentence, the court ordered Vardanyan to pay over $1.2 million in direct victim restitution for the financial damages incurred. The Ryuk ransomware, operational since at least August 2018, made headlines during the peak of the Covid-19 pandemic when its operators led a string of high-profile attacks on major healthcare facilities across the U.S.
According to court filings, Vardanyan operated as an initial access specialist within the Ryuk operation between March 2019 and June 2020. Specializing in breaking into corporate perimeters, he and his co-conspirators deployed ransomware payloads across hundreds of compromised servers and workstations.
The syndicate systematically targeted a variety of American organizations, including a technology company in Wilsonville, Oregon, a school in Texas, and a business in Michigan that paid a ransom of 200 Bitcoins, worth over $1.1 million at the time, to decrypt its operational infrastructure.
Throughout the campaign, Vardanyan and his co-conspirators extorted approximately 1,610 Bitcoins in ransom payments from victim companies, valued at over $15 million.
The Bad | TraderTraitor Backdoors Surface on Victim with No Crypto Ties
North Korean state-backed TraderTraitor, a Lazarus subgroup also known as UNC4899, PUKCHONG, or Jade Sleet, has expanded its operations beyond cryptocurrency entities to target IT service providers.
This is an extract. The publication continues at the source.
Read the original at the source: https://www.sentinelone.com/blog/the-good-the-bad-and-the-ugly-in-cybersecurity-week-39-8
Officially imported this from SentinelOne’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
Provenance
- Organization
- SentinelOne — imported from official source
- Official source
- https://www.sentinelone.com/blog/feed/ RSS
- Imported
- October 02, 2026 16:00
- Versions
- 1 recorded
- Identity
bltd8ee7609ac4c361a