Connect with us

Infosecurity

Ryuk operator pleads guilty; Blackcat/AlphV conspirator gets nearly 6-year sentence

Published

on

Ryuk ransomware operator

Two ransomware cases hit major milestones in U.S. courts

Federal prosecutors are closing in on the people who built and ran some of the most damaging ransomware operations of the past decade. This week brought two significant developments: a Ryuk operator pleaded guilty in Oregon, and a Florida man who helped the Blackcat/AlphV gang got a 70-month prison sentence.

Karen Serobovich Vardanyan, a 34-year-old Armenian national, admitted to conspiracy and computer fraud charges on Wednesday. For about six months starting in November 2019, he broke into corporate networks to deploy Ryuk ransomware, according to prosecutors.

Separately, Angelo Martino, 41, of Land O’Lakes, Florida, was sentenced to 70 months in federal prison for aiding Blackcat/AlphV extortion efforts beginning in April 2023. Martino’s case stands out because he used his day job as a ransomware negotiator to help the criminals squeeze more money out of victims.

Vardanyan’s Ryuk attacks: a Michigan company paid 200 bitcoin

Vardanyan was extradited from Ukraine to the U.S. in June 2025, after his arrest in Kyiv two months earlier. He now faces up to 15 years in prison and fines up to $500,000. He has also agreed to pay more than $1.1 million in restitution. His sentencing is set for September 22.

Prosecutors detailed some of his alleged attacks. “Vardanyan worked with his co-conspirators to attack a company in Michigan that paid 200 bitcoin or over $1.1 million at the time of payment to restore access to their network,” they said. “They also attacked a company in Wilsonville, Oregon, and in February 2020 attacked a school in Texas.”

Ryuk first appeared in August 2018, targeting large organizations with enormous ransom demands. Law enforcement and cybersecurity researchers have tied it to other major cybercrime operations, including Conti and Trickbot. International authorities have pursued Ryuk for years, successfully prosecuting one of its money launderers and sanctioning other alleged members.

Other Ryuk defendants still being pursued

Vardanyan’s case is part of a broader crackdown. Armenian national Levon Georgiyovych Avetisyan faces conspiracy, fraud, and extortion charges. Ukrainian nationals Oleg Nikolayevich Lyulyava and Andrii Leonydovich Prykhodchenko face the same charges. Prosecutors said last year that Avetisyan was in custody in France, while the two Ukrainians remained at large.

The U.S. Department of Justice has been steadily dismantling the Ryuk ecosystem, which also overlaps with the Trickbot botnet infrastructure. Each guilty plea and arrest chips away at the network’s ability to operate.

Martino: the negotiator who turned against his own clients

Martino surrendered to U.S. Marshals in March and pleaded guilty in April to an extortion charge. His story is a cautionary tale about trust in the cybersecurity industry.

Prosecutors said Martino “was paid by BlackCat attackers to provide confidential information about the negotiating position and strategy of his employer’s clients and enable the ransomware actors to maximize the ransoms paid by the victims.” In other words, he was double-dealing — collecting a salary from a legitimate firm while secretly working for the criminals on the other side of the negotiation table.

Two other men connected to the same case, Ryan Goldberg and Kevin Martin, pleaded guilty to extortion charges earlier this year. Both received four-year prison sentences in May. Martin and Martino were ransomware negotiators for DigitalMint, while Goldberg worked for incident response firm Sygnia.

DigitalMint has since implemented new controls requiring all negotiations to be conducted over cloud-based platforms that can be audited and logged. One of the company’s founders is personally overseeing all negotiations now.

What this means for ransomware enforcement

These cases show that law enforcement is willing to pursue not just the hackers who deploy ransomware, but also the people who enable them — even when those people hold legitimate jobs in the cybersecurity industry. The Martino case, in particular, sends a message to negotiators and incident responders: if you cross the line, you’ll face serious consequences.

For ransomware victims and negotiators, the takeaway is clear. Verify who you’re working with. Check backgrounds. And be aware that the person helping you negotiate could be feeding information to the attackers.

Both cases also highlight the international scope of ransomware investigations. Vardanyan was arrested in Ukraine and extradited to the U.S. Avetisyan is in French custody. The Justice Department is coordinating with allies to chase these suspects across borders.

Sentencing for Vardanyan is scheduled for September 22. Martino’s 70-month sentence is already in place. The fallout from these cases will likely continue as prosecutors pursue the remaining defendants.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Infosecurity

White House Opens Door for Private Firms to Join Offensive Cyber Strikes

Published

on

offensive cyber operations

A New Era for US Cyber Policy

The White House has quietly changed the rules of engagement in cyberspace. A new National Security Presidential Memorandum (NSPM), signed by President Donald Trump on August 12, now allows federal law enforcement to team up with private companies for offensive cyber strikes against foreign threat actors targeting the US.

This isn’t a small tweak. It’s a structural shift that brings Silicon Valley and other private firms directly into the business of hacking back — something the US government has long avoided.

The memorandum builds on an Executive Order from March that told agencies to take “rigorous actions” against cyber-enabled crime. Now, the private sector gets a formal seat at the table.

Why the Private Sector? The Rationale Behind the NSPM

The White House argues that American companies are the most innovative in the world, but their capabilities have been “historically underutilized” in the fight against cybercriminals. That’s a fair point. Many private firms already possess world-class threat intelligence and offensive capabilities — they just haven’t been allowed to use them against adversaries.

The numbers make the case compelling. American consumers reported losing more than $20.8 billion to cyber-enabled crime in 2025. Nearly three-quarters of US adults (73%) have experienced some form of online scam or attack. The status quo isn’t working.

So the NSPM creates a framework where private companies can enter into agreements with other firms and government bodies — federal, state, and local — to gather threat intelligence and propose cyber operations designed to disrupt transnational crime groups.

How the Program Will Work

The Homeland Security Task Force’s National Coordination Center (NCC) will run the show. Two Executive Directors — one from the Department of Justice, one from the Department of Homeland Security — will oversee operations.

The memorandum promises “rigorous procedures” for reviewing and conducting “limited” cyber operations. These won’t be free-for-alls. All operations will be directed by the US government, and the program must comply with the Constitution, US laws, and international agreements.

Still, the language is deliberately broad. “Every available tool” should be deployed against transnational cyber threats, the White House insists.

Industry Reactions: Welcome, Caution, and Fear

The cybersecurity community is split. Some see this as a long-overdue evolution. Others see a recipe for disaster.

Chris Wysopal, co-founder of Veracode, called the policy a “big shift” on X. His take: “Not exactly ‘hack back,’ but definitely a major expansion of the private sector’s role in offensive cyber operations.”

That’s the optimistic read. The pessimistic one comes from people who’ve actually done this work.

The Attribution Problem

Nick Carr, technical director for the Microsoft Threat Intelligence Center (MSTIC) and a former chief technical analyst at CISA, knows the terrain better than most. He ran the global cybercrime and ransomware intelligence team for almost four years.

His warning is blunt: attribution in criminal operations is extremely difficult. “Few organizations can repeatably do it right (including certain gov agencies),” he wrote on X. “People are regularly and willingly wrong on pretty important incidents.”

That’s a chilling thought when private firms are about to get a license to strike.

Escalation Risks

Dr. Lukasz Olejnik, an independent cybersecurity and privacy researcher, raised another red flag. He warned that authorizing private firms to destroy cyber-controlled infrastructure could hit state-linked systems. That raises the risk of interstate escalation — a cyber skirmish turning into a diplomatic crisis or worse.

The line between criminal groups and state actors is blurry. Ransomware gangs often operate with tacit state approval. A private company aiming at a criminal server might accidentally take down something connected to a foreign government. Then what?

Global Context: The UK’s Playbook

The US isn’t alone in this direction. The UK created its National Cyber Force (NCF) in 2020, and in 2023 published principles on how it uses offensive capabilities. The UK’s stance: these tools are rarely deployed, and only when other responses aren’t better suited.

That’s a more cautious approach than what the NSPM describes. The American version leans harder into private sector involvement, which is a distinctly US twist on the model.

What This Means for Businesses and Individuals

For everyday Americans, the practical impact is unclear — for now. The program is still being set up. The NCC has to establish procedures, and companies need to opt in.

But the direction is unmistakable. The US government is signaling that cybercrime is a national security threat worthy of offensive action, and that private companies will be part of the solution.

If you’re a business owner, this could mean new opportunities to collaborate with federal agencies on threat intel. It could also mean new risks if your company gets drawn into operations with unclear legal boundaries.

For the broader cybersecurity landscape, this is a paradigm shift. The question isn’t whether private sector offensive action will happen — it’s whether the guardrails will hold.

Related: how to protect yourself from cybercrime and the latest ransomware trends.

Continue Reading

Infosecurity

Europe revives CSAM scanning law for big tech: what now?

Published

on

CSAM scanning law

A controversial rule is back

The European Parliament has voted to bring back a rule that lets big tech companies scan users’ private messages for child sexual abuse material (CSAM). The decision, made on July 10th, 2026, came just before summer recess and has reignited a fierce privacy debate.

Critics call the process “Chat Control.” Supporters say it’s a necessary tool to protect children. The law, which first took effect in 2021, expired in April after Parliament failed to agree on a path forward amid widespread privacy concerns.

Now, with Thursday’s vote, companies like Google, Microsoft, and Meta have legal cover to continue scanning until 2028. But the way the vote happened has many people worried.

How did the vote pass?

The vote used an unusual legislative procedure. It required an absolute majority to kill the provision. That means all lawmakers who weren’t present in the chamber were counted as “yes” votes. So even though more present members opposed the measure than supported it, the rule passed.

Parliament President Roberta Metsola had pushed hard for renewing the rule. She and other officials argued it was urgent. The rule doesn’t allow scanning on encrypted platforms like Signal, but critics say the broader implications are still troubling.

This isn’t the first time Parliament considered the measure. Three months ago, under normal voting conditions, lawmakers rejected it. The procedural maneuver this time felt like an end-run around that decision.

What critics are saying

Privacy advocates are furious. Rand Hammoud of Europe’s Center for Democracy and Technology called the tactics “highly politicised procedural efforts” in a blog post. He accused lawmakers of “overstepping Parliament’s own mandate and previous vote.”

Simeon de Brouwer, a policy adviser at European Digital Rights, put it more bluntly. He said Chat Control allows tech companies to “snoop without a warrant, with little to no oversight, and with no legal basis, on millions of conversations.”

That’s a strong claim. But it reflects the deep unease many feel about giving corporations the power to inspect private messages.

The bigger battle: Chat Control 2.0

Thursday’s vote is just the opening skirmish. A much larger fight is brewing over what insiders call Chat Control 2.0.

In its most extreme form, 2.0 could force service providers to scan conversations and hosted content, including end-to-end encrypted communications. That would be a massive shift from the voluntary, limited scanning allowed under the current rule.

Lawmakers have been negotiating a permanent framework since November 2023. Progress has been slow. Law enforcement agencies, however, are pushing hard for a permanent solution.

Europol’s position

When the law lapsed in April, Catherine De Bolle, the executive director of Europol, issued a statement. She said that “enabling online service providers to continue detecting and reporting suspected CSAM to the competent authorities is vital for the protection of children.”

That’s a powerful argument. No one wants to make it easier for predators to operate. But de Brouwer and others say the tradeoffs are too high.

What happens next?

The renewed rule gives big tech legal protection to continue scans until 2028. But the debate over Chat Control 2.0 is far from over.

If you care about digital privacy rights, this is a story to watch. The outcome could reshape how European governments balance child protection against surveillance concerns.

For now, the scans continue. The legal cover is in place. And the critics are watching closely.

Continue Reading

Infosecurity

VMware vCenter Vulnerability Exploited Just Five Days After Patch Release

Published

on

vCenter flaw exploited

Critical vCenter Flaw Exploited Within Days of Disclosure

Attackers wasted no time. A critical VMware vCenter vulnerability was exploited just five days after Broadcom published its advisory. The campaign used an open-source reverse shell to keep access to compromised systems.

German digital forensics firm Quirso uncovered the activity during an incident response engagement. Its findings, released on August 10, point to a suspected advanced persistent threat (APT) actor. Quirso counted 361 victim IP addresses across 47 countries, though it cautioned that an IP address doesn’t always equal a single organization.

The vulnerability, tracked as CVE-2026-59310, is a critical directory traversal flaw in the vCenter Syslog server. It carries a CVSS score of 9.8. Broadcom said an unauthenticated attacker with network access to vCenter can exploit it to execute arbitrary code. That turns a service built to collect logs into a direct route into the operating system.

For more on VMware-related threats, see Play Ransomware Expands to Target VMware ESXi Environments.

Five Days From Advisory to Compromise

Broadcom released its advisory on July 29. At that point, it said it had not observed any exploitation. The advisory was revised on August 3 to include 8.0 U2f express patches.

Quirso’s team first noticed compromised systems contacting attacker infrastructure on August 3. The next day brought 151 more victim IPs. By August 5, roughly 95% of the total 361 had appeared. Germany, the United States, Turkey, Iran, and France accounted for 185 of them.

The correlation between disclosure and exploitation is striking. While the attacker may have had prior knowledge of the flaw, Quirso believes the advisory likely served as the campaign’s starting point.

Two Clocks to Manage

For persistence, the attackers deployed reverse_ssh, an open-source SSH-based reverse shell framework built for penetration testing. Because it dials outward rather than accepting inbound connections, it can bypass controls designed to block unsolicited inbound access. Quirso stressed that its presence alone does not prove compromise.

Jason Soroko, senior fellow at certificate lifecycle management provider Sectigo, said patching alone won’t resolve the incident. “There are therefore two clocks to manage,” he said. One for closing the vulnerability, and another for evicting anyone who entered before the patch was applied.

What to Check Right Now

  • Look for outbound SSH connections from vCenter servers to unknown IPs.
  • Review logs for unusual activity around August 3–5, 2026.
  • Check for the presence of reverse_ssh binaries or related processes.
  • Assume compromise if any indicators are found, and initiate incident response immediately.

Patch Availability and Workarounds

Broadcom has not published a workaround. Fixed vCenter releases are 9.1.0.0300, 9.0.2.0100, and 8.0 U3k or 8.0 U2f depending on the deployed branch. These address both critical flaws in the advisory: the exploited directory traversal and an authentication bypass in VMware Directory Service.

If you haven’t patched yet, do it now. The window between disclosure and exploitation is shrinking, and this campaign shows how quickly attackers move.

For more on securing your infrastructure, read about VMware vCenter vulnerability remediation steps and how to detect reverse shells in your environment.

Continue Reading

Trending