Karen Serobovich Vardanyan, a 34-year-old Armenian national, has pleaded guilty to conspiracy and computer fraud for his role in deploying Ryuk ransomware, a notorious malware strain that has been used to extort millions of dollars from victims.
Ryuk Ransomware Attacks
According to prosecutors, Vardanyan accessed companies' computer networks to deploy Ryuk ransomware for about six months, beginning in November 2019. He faces up to 15 years in prison and as much as $500,000 in fines, and has agreed to pay more than $1.1 million in restitution.
Vardanyan's case is connected to others still being pursued by U.S. prosecutors, including Armenian national Levon Georgiyovych Avetisyan, who has been charged with conspiracy, fraud, and extortion.
Blackcat/AlphV Conspirator Sentenced
Meanwhile, Angelo Martino, a 41-year-old man from Land O'Lakes, Florida, has been sentenced to 70 months in federal prison for his role in helping the Blackcat/AlphV gang extort multiple victims. Martino, a former ransomware negotiator, used his experience to help the cybercriminals maximize their ransom demands.
Martino pleaded guilty to an extortion charge in April and surrendered himself to U.S. Marshals in March. Two other men connected to the same case, Ryan Goldberg and Kevin Martin, pleaded guilty to extortion charges earlier this year and were given four-year prison sentences in May.
International Efforts to Combat Ransomware
International authorities have been targeting Ryuk and other major ransomware groups for years, with several successful prosecutions and sanctions against alleged members. The U.S. government has also been working to disrupt and dismantle these groups, with the Department of Justice announcing several major takedowns in recent years.
The case against Vardanyan and others highlights the ongoing threat posed by ransomware and the importance of international cooperation in combating these crimes. As the use of ransomware continues to evolve and spread, it is likely that we will see more cases like this in the future.
Ryuk Ransomware History
Ryuk ransomware was first detected in August 2018, when it began attacking large organizations with demands for high ransom payments. Since then, it has been connected to other major cybercrime operations, including Conti and Trickbot.
Law enforcement agencies and cybersecurity researchers have been working to track and disrupt the activities of Ryuk and other ransomware groups, with several successful operations in recent years. However, the threat posed by these groups remains significant, and ongoing efforts are needed to protect against these types of attacks.
DigitalMint, the company where Martino worked, has instituted several new controls to prevent similar incidents in the future, including mandating that all negotiations be conducted over cloud-based platforms that can be audited and logged. One of the company's founders is personally overseeing all negotiations.
The sentences handed down in these cases serve as a reminder of the serious consequences that can result from participating in ransomware attacks. As the threat landscape continues to evolve, it is essential that individuals and organizations take proactive steps to protect themselves against these types of threats.
- Karen Serobovich Vardanyan pleaded guilty to conspiracy and computer fraud
- Angelo Martino was sentenced to 70 months in federal prison for his role in helping the Blackcat/AlphV gang
- Ryuk ransomware was first detected in August 2018
- DigitalMint has instituted new controls to prevent similar incidents in the future
The fight against ransomware is an ongoing battle, with new threats and challenges emerging all the time. However, with the help of international cooperation and the efforts of law enforcement agencies and cybersecurity researchers, it is possible to make a significant impact and protect against these types of attacks.
Source: The Record