A Zurich District Court sentenced a 52-year-old Ukrainian developer to 12 years and nine months in prison for creating code used by the LockerGoga, MegaCortex, and Nefilim ransomware operations. The court also imposed a 10-year ban on entering Switzerland, although the judgment remains subject to appeal. It found the defendant was a developer rather than the organizer of the criminal enterprises and rejected his claim that the source code recovered from his home was built for an unidentified cybersecurity-consulting client; extortion messages in his data helped undermine that defense.
The conviction covered the developer's role in ransomware attacks including Nefilim's 2020 intrusion at Swiss rail manufacturer Stadler Rail, as well as attacks on Meier Tobler and Crealogix. U.S. authorities have separately indicted alleged operation mastermind Volodymyr Tymoshchuk, who remains at large, is listed by the FBI as wanted, and is associated with an $11 million reward offer.

See the reporting duties and controls this puts on the clock.
6 events from the most recent confirmed update back to the earliest known activity.
U.S. prosecutors formally indicted Volodymyr Tymoshchuk as the alleged mastermind of the LockerGoga, MegaCortex, and Nefilim operations. He remained at large, with the FBI offering up to $11 million for information leading to the arrest or conviction of him or other key leaders.
Zurich prosecutors stated in September 2022 that the suspect arrested in October 2021 was suspected of money laundering and data corruption. They alleged associated ransomware operators attacked more than 1,800 people and institutions in 71 countries, causing losses of several hundred million Swiss francs.
Swiss authorities arrested a suspect who was subsequently held in pretrial detention from October 2021. The law-enforcement action also identified other alleged LockerGoga, MegaCortex, and Nefilim members, who were not named.
The court found the Ukrainian developer played a key role in the May 2020 Nefilim attack on Swiss rolling-stock manufacturer Stadler Rail. Stadler said the incident likely caused a data leak and involved threats to publish stolen files; it refused a reported $6 million ransom demand.
U.S. prosecutors later alleged that Volodymyr Tymoshchuk was responsible for the 2019 ransomware attack against Norsk Hydro, among at least 250 targeted companies.
Zurich District Court sentenced a 52-year-old Ukrainian developer to 12 years and nine months in prison and imposed a 10-year Swiss entry ban for code used by LockerGoga, MegaCortex, and Nefilim. The court found he was a developer rather than the operations' mastermind, rejected his consulting-client explanation after finding extortion messages in his data, and left the judgment open to appeal.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourcetheregister.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.