ZCyberNews
中文
Industry NewsHigh3 min read

Ukrainian faces 12 years in Swiss ransomware trial

Swiss prosecutors seek 12 years for a Ukrainian developer tied to LockerGoga, MegaCortex, and Nefilim attacks on Stadler Rail and others, with $160M in losses.

Zurich District Court building where the ransomware trial is taking place

Executive Summary

Swiss prosecutors are seeking a 12-year prison sentence for a 52-year-old Ukrainian software developer accused of playing a key role in an international ransomware operation that caused hundreds of millions of dollars in damage. The trial, which opened Monday at the Zurich District Court, centers on attacks using LockerGoga, MegaCortex, and Nefilim ransomware against Swiss companies including train manufacturer Stadler Rail, banking software developer Crealogix, and building technology firm Meier Tobler. The defendant, whose name has not been publicly released, denies developing malware or participating in any attacks.

Technical Analysis

The prosecution alleges the defendant directly participated in attacks against 10 companies in Switzerland and other countries between December 2018 and May 2020, causing more than 130 million Swiss francs ($160 million) in estimated losses, including lost revenue and system rebuild costs. The ransomware families involved—LockerGoga, MegaCortex, and Nefilim—have been linked to a cybercriminal group that hacked corporate networks, stole data, and encrypted systems to extort victims.

According to Swiss journalists who attended the hearing, prosecutors claim another Ukrainian hacker, Oleksandr Ieremenko, who operated from Moscow, directed the attacks carried out by the defendant in Switzerland. Ieremenko reportedly died after falling from a window in Moscow in 2022, though prosecutors could not establish whether his death was an accident, suicide, or killing. Swiss prosecutors cited testimony from a source in Ukraine alleging Ieremenko enjoyed protection from Russia's Federal Security Service (FSB). However, they did not present evidence that the defendant had direct ties to Russian intelligence.

The defendant rejected the prosecution's account, telling the court that ransomware source code found on his devices came from a cybersecurity client for whom he had worked as a consultant. His defense also questioned the digital evidence, arguing that investigators failed to maintain complete records of the data they seized.

The case stems from an investigation launched after ransomware attacks against companies in Zurich in 2019. It expanded into an international operation involving authorities in Switzerland, France, the Netherlands, Norway, Ukraine, and the United States.

Mitigations & Recommendations

While this trial does not present a new technical vulnerability, defenders should monitor the outcome for insights into the operational structure of ransomware groups using LockerGoga, MegaCortex, and Nefilim. The case highlights the importance of preserving complete digital evidence chains in ransomware investigations. Organizations that have been victims of these ransomware families should review their incident response procedures and ensure that any forensic data collected is properly documented to support potential legal action. Additionally, companies in manufacturing and financial services sectors should remain alert to the ongoing threat posed by these ransomware variants, which continue to be used in attacks.

Stay Updated

Get the latest cybersecurity news delivered to your inbox.

Tags:#lockergoga#megacortex#nefilim#ransomware#switzerland#stadler-rail

Related Articles