The Good, the Bad and the Ugly in Cybersecurity – Week 39 (2026)

Imported from official source

Cybersecurity Classified by Officially

The Good | U.S. Court Sentences Initial Access Specialist Tied to Ryuk Ransomware

A court has sentenced Armenian citizen Karen Serobovich Vardanyan to two years in federal prison and three years of supervised release for his role in launching high-profile Ryuk ransomware attacks against corporate networks throughout the United States. Vardanyan, also known online as ‘Maneeken’ or ‘Karl Lagerfeld’, was originally extradited to Oregon from Kyiv, Ukraine, in a coordinated effort between international law enforcement authorities. 

In addition to his custodial sentence, the court ordered Vardanyan to pay over $1.2 million in direct victim restitution for the financial damages incurred. The Ryuk ransomware, operational since at least August 2018, made headlines during the peak of the Covid-19 pandemic when its operators led a string of high-profile attacks on major healthcare facilities across the U.S.

According to court filings, Vardanyan operated as an initial access specialist within the Ryuk operation between March 2019 and June 2020. Specializing in breaking into corporate perimeters, he and his co-conspirators deployed ransomware payloads across hundreds of compromised servers and workstations. 

The syndicate systematically targeted a variety of American organizations, including a technology company in Wilsonville, Oregon, a school in Texas, and a business in Michigan that paid a ransom of 200 Bitcoins, worth over $1.1 million at the time, to decrypt its operational infrastructure.

Throughout the campaign, Vardanyan and his co-conspirators extorted approximately 1,610 Bitcoins in ransom payments from victim companies, valued at over $15 million. 

The Bad | TraderTraitor Backdoors Surface on Victim with No Crypto Ties

North Korean state-backed TraderTraitor, a Lazarus subgroup also known as UNC4899, PUKCHONG, or Jade Sleet, has expanded its operations beyond cryptocurrency entities to target IT service providers. 

This is an extract. The publication continues at the source.

Read the original at the source: https://www.sentinelone.com/blog/the-good-the-bad-and-the-ugly-in-cybersecurity-week-39-8

Officially imported this from SentinelOne’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

Provenance

Organization
SentinelOne — imported from official source
Official source
https://www.sentinelone.com/blog/feed/ RSS
Imported
October 02, 2026 16:00
Versions
1 recorded
Identity
bltd8ee7609ac4c361a

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.