Skip to main content
GBU_week39_2026.jpg
The Good, the Bad and the Ugly

The Good, the Bad and the Ugly in Cybersecurity – Week 39 (2026)

作成者 SentinelOne

The Good | U.S. Court Sentences Initial Access Specialist Tied to Ryuk Ransomware

A court has sentenced Armenian citizen Karen Serobovich Vardanyan to two years in federal prison and three years of supervised release for his role in launching high-profile Ryuk ransomware attacks against corporate networks throughout the United States. Vardanyan, also known online as ‘Maneeken’ or ‘Karl Lagerfeld’, was originally extradited to Oregon from Kyiv, Ukraine, in a coordinated effort between international law enforcement authorities. 

Karen_Serobovich_Vardanyan.jpg
Vardanyan’s arrest (Source: National Police of Ukraine)

In addition to his custodial sentence, the court ordered Vardanyan to pay over $1.2 million in direct victim restitution for the financial damages incurred. The Ryuk ransomware, operational since at least August 2018, made headlines during the peak of the Covid-19 pandemic when its operators led a string of high-profile attacks on major healthcare facilities across the U.S.

According to court filings, Vardanyan operated as an initial access specialist within the Ryuk operation between March 2019 and June 2020. Specializing in breaking into corporate perimeters, he and his co-conspirators deployed ransomware payloads across hundreds of compromised servers and workstations. 

The syndicate systematically targeted a variety of American organizations, including a technology company in Wilsonville, Oregon, a school in Texas, and a business in Michigan that paid a ransom of 200 Bitcoins, worth over $1.1 million at the time, to decrypt its operational infrastructure.

Throughout the campaign, Vardanyan and his co-conspirators extorted approximately 1,610 Bitcoins in ransom payments from victim companies, valued at over $15 million. 

The Bad | TraderTraitor Backdoors Surface on Victim with No Crypto Ties

North Korean state-backed TraderTraitor, a Lazarus subgroup also known as UNC4899, PUKCHONG, or Jade Sleet, has expanded its operations beyond cryptocurrency entities to target IT service providers. 

Following a compromise of LayerZero Labs in April, SentinelLABS identified a second victim an IT services firm based in India, infected with the same two macOS Rust-based backdoors, dubbed FLATROOF and ROOFDECK. The intrusion points to an evolving strategy where DPRK state-sponsored actors systematically target developer endpoints and software supply chains, regardless of an organization's direct relationship to digital assets.

The attack chain relies on social engineering schemes disguised as fake job interviews, a common approach also seen in Contagious Interview campaigns. Threat actors contact DevOps and infrastructure engineers with invitations to review candidate coding repositories hosted on GitHub. These project repositories contain weaponized Terraform lock files that specify custom provider registries hosted on attacker-controlled domains, such as typosquatted HashiCorp registries. 

terraform_fake_interview.jpg
Interview task from a GitHub repository containing a weaponized .terraform.lock.hcl file

When an unsuspecting engineer executes standard initialization commands, Terraform treats the malicious provider as the source of truth, downloading and executing backdoor modules directly on the developer's workstation.

TraderTraitor operators gained initial access to an Apple Silicon MacBook belonging to a DevOps engineer from the newly identified victim in India. They deployed FLATROOF to execute shell commands and exfiltrate browser data, command histories, and system keychains via Telegram bots. FLATROOF then suppressed Gatekeeper security controls to launch ROOFDECK, a backdoor that leverages the decentralized Nostr protocol for command-and-control server resolution. 

Since developer workstations possess elevated cloud credentials and source control access, securing development environments against supply chain lures remains critical for modern enterprise defense.

The Ugly | Lone Operator Uses AI Agents to Steal 600K Credit Cards in Mass Skimming Campaign

A financially-motivated threat actor recently deployed open-source AI agent frameworks to attack hundreds of online retailers at scale, compromising more than 100 e-commerce websites and exfiltrating over 600,000 credit card records. Active since July 2026, the campaign has leveraged three specialized AI tools to execute the complete attack chain across target networks with minimal human intervention.

The automated framework relied on Strix, an AI penetration testing framework that conducted 633 hours of vulnerability scanning in a nine-day window across 138 targeted hosts. Upon identifying exploitable entry points, the operator deployed Cairn, an autonomous exploitation engine tasked with obtaining administrative access and system shells. Campaign orchestration was then governed by Hermes, an AI agent configured with a specialized red team operator persona containing 78 distinct attack-related skills. 

timeline_attacks_cairn.jpg
Timeline of attacks orchestrated by Cairn between September 10-15 2026 (Source: Gambit)

Once a human operator supplied a target list and brief tactical objectives, the AI agents autonomously navigated custom software architectures and selected an attack path in real time through probing. 

To harvest payment data, the autonomous agents injected digital skimmers across compromised environments by adding malicious code to legitimate JavaScript files, poisoning cloud storage buckets, altering Kubernetes deployments, and establishing persistence via scheduled cron jobs. After exfiltrating credit card records, Hermes executed automated cleanup routines that systematically wiped source database fields in batches, inflicting severe operational data loss on victim retailers.

Researchers found that the entire campaign operated at an average cost of just $25 per targeted company. Major targets so far include a Fortune 500 hospitality firm, a major U.S. airline, an online fashion retailer, and an industrial supplies distributor. 

Related Articles

Decorative background gradient

Subscribe

Get the Latest From the SentinelOne Blog