Full Report
An Armenian citizen extradited from Ukraine was sentenced Tuesday to two years in federal prison for his role in a ransomware scheme that targeted companies in the United States, including one in Oregon, according to the U.S. Attorney’s Office for the District of Oregon. Karen Vardanyan, 35, was also sentenced to three years of supervised release and ordered to pay $1,219,106 in restitution to victims, according to the U.S. Attorney’s Office. Prosecutors said Vardanyan was part of a group that used Ryuk ransomware to lock victims out of their computer systems and demand payments. The ransomware was used against companies, schools and other organizations around the world from March 2019 through about June 2020, according to court documents cited by prosecutors.
Analysis Summary
# Incident Report: Ryuk Ransomware Campaign (Karen Vardanyan Case)
## Executive Summary
From March 2019 to June 2020, an Armenian national, Karen Vardanyan, participated in a global cybercriminal group utilizing Ryuk ransomware to extort millions from schools, companies, and organizations. The campaign resulted in significant operational disruption and financial losses, leading to the eventual extradition of Vardanyan from Ukraine and a federal prison sentence in the United States.
## Incident Details
- **Discovery Date:** Not explicitly disclosed (Investigation spanned 2019–2024)
- **Incident Date:** March 2019 – June 2020 (Active Campaign Period)
- **Affected Organization:** Multiple (including an unnamed Oregon-based company)
- **Sector:** Education, Private Sector, and Critical Infrastructure
- **Geography:** United States (Oregon and others) and worldwide
## Timeline of Events
### Initial Access
- **Date/Time:** Commencing March 2019
- **Vector:** Likely phishing or secondary infections (common Ryuk vectors)
- **Details:** Vardanyan and his associates targeted high-value organizations to deploy Ryuk ransomware.
### Lateral Movement
- **Details:** The group moved through victim networks to identify critical systems and backup servers to maximize the impact of the encryption.
### Data Exfiltration/Impact
- **Details:** Systems were encrypted, locking victims out of their data. In line with Ryuk tactics, the group demanded cryptocurrency payments for decryption keys.
### Detection & Response
- **How it was discovered:** Victims reported system lockouts and ransom notes appearing on workstations.
- **Response actions taken:** Federal investigation by U.S. authorities, international law enforcement cooperation leading to Vardanyan's arrest in Ukraine, and subsequent extradition to the U.S.
## Attack Methodology
- **Initial Access:** Ryuk typically utilizes TrickBot or Emotet infections as a precursor.
- **Persistence:** Implementation of scheduled tasks and registry key modifications.
- **Privilege Escalation:** Exploitation of administrative credentials and domain controller access.
- **Defense Evasion:** Disabling of antivirus software and deletion of Volume Shadow Copies.
- **Credential Access:** Scraping memory for clear-text passwords (e.g., Mimikatz).
- **Discovery:** Network scanning to identify high-value targets and file shares.
- **Lateral Movement:** Remote Desktop Protocol (RDP) and PowerShell Remoting.
- **Impact:** Data encryption using RSA-4096 and AES-256 algorithms to render files inaccessible.
## Impact Assessment
- **Financial:** $1,219,106 ordered in restitution; global losses for Ryuk victims are estimated in the hundreds of millions.
- **Data Breach:** Compromise of sensitive corporate and educational data.
- **Operational:** Total cessation of business and educational activities during the encryption phase.
- **Reputational:** Significant public impact for targeted schools and healthcare providers.
## Indicators of Compromise
- **File indicators:** `.ryuk` extension on encrypted files; `RyukReadMe.txt` ransom notes.
- **Behavioral indicators:** Unusual RDP traffic, deletion of shadow copies using `vssadmin.exe`, and stopping of SQL/Exchange services.
## Response Actions
- **Containment:** Victims typically isolated infected hosts and disconnected from the internet.
- **Eradication:** Law enforcement neutralized the specific cell involving Vardanyan.
- **Recovery:** Restoration from backups (where available) or manual system rebuilds.
## Lessons Learned
- **Key takeaways:** Ransomware remains a collaborative international effort; individual actors in the supply chain (like Vardanyan) are vital links for law enforcement to target.
- **What could have been done better:** Early detection of precursor infections (TrickBot/Emotet) could have prevented the final Ryuk deployment.
## Recommendations
- **Multi-Factor Authentication (MFA):** Enforce MFA on all remote access points (VPN, RDP).
- **Offline Backups:** Maintain immutable, air-gapped backups to ensure recovery without paying ransoms.
- **Endpoint Detection and Response (EDR):** Deploy EDR tools to detect behavioral anomalies such as the mass deletion of shadow copies.
- **International Cooperation:** Continue supporting inter-agency intelligence sharing to track threat actors operating in non-extradition-friendly jurisdictions.