A Zurich District Court sentenced a 52-year-old Ukrainian IT specialist to 12 years and nine months in prison for serving as the lead developer of the LockerGoga, MegaCortex, and Nefilim ransomware families. The malware encrypted victim data for extortion campaigns that caused an estimated CHF 100 million (about EUR 106 million) in losses, including attacks on Swiss companies Stadler Rail, Meier Tobler, and Crealogix. Stadler Rail was targeted in May 2020 with a bitcoin ransom demand then valued at about USD 6 million.
The conviction followed an international investigation supported by France's anti-cybercrime office, which traced the operation through a France-hosted command-and-control server and ransom-payment flows. Investigators mapped infrastructure involving TrickBot and Cobalt Strike and helped enable release of a LockerGoga decryptor. The defendant denied involvement and may appeal; the court also imposed a 10-year ban from Switzerland. Prosecutors alleged an instigator had Russian-intelligence links, but the record did not establish that the convicted developer directly worked for Russian intelligence.

See the reporting duties and controls this puts on the clock.
6 events from the most recent confirmed update back to the earliest known activity.
A Zurich District Court sentenced the 52-year-old Ukrainian IT specialist to 12 years and nine months in prison for his key role in ransomware extortion operations, finding him to be the lead developer of LockerGoga, MegaCortex, and Nefilim. The court also imposed a 10-year ban from Switzerland; the judgment remains subject to appeal.
The alleged instigator of the ransomware operations reportedly died after falling from a window in Moscow. Prosecutors said he had allegedly cooperated with Russian secret services, though the court record contained no evidence of the defendant's direct links to those services.
Swiss authorities arrested the Ukrainian IT specialist following an international investigation supported by France's anti-cybercrime office. He was also subject to a French extradition request and remained in pre-trial detention.
Attackers targeted Swiss train manufacturer Stadler Rail, stole about 500 GB of confidential data, and demanded a bitcoin ransom valued at approximately USD 6 million. Stadler Rail refused to pay.
French energy-services company Spie and engineering consultancy Altran were targeted by the LockerGoga, MegaCortex, and Nefilim ransomware families.
French anti-cybercrime investigators identified a France-based command-and-control server rented by a Ukrainian national, traced ransom-payment flows to a suspect in Switzerland, and mapped infrastructure using TrickBot and Cobalt Strike. The international operation also led to publication of a LockerGoga decryptor.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.