Swiss prosecutors have asked a court to sentence a 52-year-old Ukrainian software developer to 12 years in prison for allegedly helping run ransomware attacks tied to LockerGoga, MegaCortex, and Nefilim. The case alleges he participated in intrusions, data theft, and system encryption used to extort at least 10 companies in Switzerland and other countries between late 2018 and mid-2020, causing estimated losses of more than 130 million Swiss francs. Named victims include Stadler Rail, Crealogix, and Meier Tobler, and prosecutors are also seeking his expulsion from Switzerland for 12 years and the recovery of 1.8 million Swiss francs in alleged criminal proceeds.
The defendant denied creating malware or taking part in ransomware attacks, arguing that source code found on his devices came from legitimate consulting work for a cybersecurity client and disputing the integrity of seized digital evidence. The prosecution said the wider operation was directed by another Ukrainian hacker, Oleksandr Ieremenko, allegedly operating from Moscow and possibly benefiting from FSB protection, while stopping short of alleging direct Russian intelligence ties for the defendant. The investigation began after ransomware attacks in Zurich in 2019 and grew into a multinational law enforcement effort involving Switzerland, France, the Netherlands, Norway, Ukraine, and the United States.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
At the Zurich trial, prosecutors identified Stadler Rail, Crealogix, and Meier Tobler among the 10 companies allegedly targeted by the LockerGoga, MegaCortex, and Nefilim ransomware operation. The named attacks were part of the broader campaign prosecutors say caused more than 130 million Swiss francs in losses.
Prosecutors said alleged attack director Oleksandr Ieremenko died after falling from a window in Moscow in 2022. They said they could not determine whether the death was an accident, suicide, or killing.
The defendant in the Swiss ransomware case has been in custody since October 2021. Prosecutors accuse him of playing a key role in attacks tied to LockerGoga, MegaCortex, and Nefilim.
Swiss authorities launched an investigation after ransomware attacks against companies in Zurich in 2019. The case later expanded into an international operation involving authorities in Switzerland, France, the Netherlands, Norway, Ukraine, and the United States.
Zurich prosecutors alleged that a cybercriminal group, with the defendant as a direct participant, attacked 10 companies in Switzerland and other countries using LockerGoga, MegaCortex, and Nefilim. The alleged attacks occurred between December 2018 and May 2020 and caused more than 130 million Swiss francs in losses.
In closing arguments at the Zurich District Court trial, the prosecutor said the malware attacks against Western companies fit a deliberate Russian strategy to cause disruption and targeted damage. He also said the alleged mastermind cooperated with the FSB, while the indictment did not establish a direct link between the defendant and Russian intelligence services.
The 52-year-old Ukrainian software developer went on trial in Zurich District Court on Monday, where prosecutors sought a 12-year prison sentence, expulsion from Switzerland for 12 years, and recovery of 1.8 million Swiss francs in alleged criminal proceeds. The defendant denied developing malware or participating in ransomware attacks and challenged the integrity of seized digital evidence.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourcecyberveille.ch
Open sourcebluewin.ch
Open sourcetherecord.media
Open sourcewatson.ch
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.