Illustrative image generated with AI
Switzerland Seeks 12-Year Sentence for Developer Linked to LockerGoga, MegaCortex, and Nefilim
Swiss prosecutors demand a 12-year prison term for a Ukrainian developer accused of leading ransomware attacks causing CHF 130M in damages.
Text generated by artificial intelligence, published without human review. AI transparency
Prosecution: Ten Companies Targeted, Causing More Than CHF 130 Million in Damages
Swiss prosecutors have sought a 12-year prison sentence for a 52-year-old Ukrainian software developer standing trial before the Zurich District Court. The authorities have not disclosed his identity.
The man is accused of playing a central role in an international ransomware operation associated with the LockerGoga, MegaCortex, and Nefilim families. Prosecutors allege that he was the lead developer for an unidentified criminal group involved in compromising corporate networks, stealing data, and encrypting systems to extort payments from victims.
The alleged attacks took place between December 2018 and May 2020. They directly affected ten companies in Switzerland and other countries, causing losses exceeding CHF 130 million, or approximately $160 million.
The estimate includes both revenue lost during business disruptions and the costs of rebuilding infrastructure, systems, and data. It therefore covers more than any ransoms that may have been paid, reflecting the overall economic impact attributed to the attacks.
The companies named in the proceedings include Stadler Rail, a Swiss train manufacturer, Crealogix, which develops banking software, and Meier Tobler, a provider of building technology solutions.
Alleged Technical Role in the Criminal Operation
The case describes a multi-stage attack chain. The attackers allegedly gained access to corporate networks, stole information, and then encrypted systems and data, rendering them unusable for the affected organizations.
This combination increases pressure on victims. Encryption disrupts day-to-day operations, while data theft gives extortionists additional leverage: the information can be used to threaten publication or other consequences.
The defendant is alleged to have served as the lead developer. Prosecutors do not portray him merely as an operator with network access, but as someone involved in developing or managing the tools used during the intrusions. However, the court brief does not disclose details about the code, initial-access techniques, exploited vulnerabilities, or the precise methods used to exfiltrate data.
The three malware families cited in the case are associated with ransomware campaigns known to have targeted organizations across multiple sectors. In the Swiss case, their use allegedly caused damage across the industrial, financial, and technology sectors.
The proceedings put the losses from the ten alleged attacks at more than CHF 130 million. The broader international operation is believed to have caused damage amounting to hundreds of millions of dollars, but it is unclear what portion is directly attributable to the conduct under review by the Zurich court.
Defense Denies Developing the Malware
The defendant denies developing ransomware or participating in cyberattacks. He claims that the source code found on his devices came from a cybersecurity client for whom he worked as a consultant.
This defense seeks to distinguish possession of the code from its criminal use. Retaining malware tools or samples can have legitimate professional purposes in malware analysis, incident response, or security research. In this case, the court will have to determine whether the presence of the code is consistent with the defendant’s stated work or instead indicates operational involvement in the attacks.
The defense has also challenged the reliability of the digital evidence. His lawyers argue that investigators failed to maintain complete documentation of the data collected during the searches.
The issue concerns the chain of custody of the evidence. To establish that a file, device, or log entry can be used in court, investigators must document its acquisition, preservation, and analysis. Gaps in that process can affect evidentiary weight, particularly when prosecutors link code, devices, and criminal activity.
Based on the available information, it is not known which specific files were collected, which metadata was examined, or which forensic procedures were applied.
Possible Coordination and the Limits of the Russian Links
Prosecutors allege that another Ukrainian hacker, Oleksandr Ieremenko, operating from Moscow, coordinated the attacks carried out by the defendant in Switzerland.
The prosecution cited testimony from a source in Ukraine who claimed that Ieremenko benefited from the protection of Russia’s Federal Security Service, or FSB. Ieremenko reportedly died after falling from a window in Moscow in 2022. It has not been established whether his death was an accident, suicide, or homicide.
The proceedings have not, however, presented evidence of direct links between the defendant and Russian intelligence. The alleged protection of Ieremenko therefore does not, by itself, establish that the defendant had ties to Russian state agencies.
This distinction is significant in a case involving transnational cybercrime, infrastructure spread across multiple countries, and suspicions surrounding operators based in Russia. The court will have to determine which elements can be directly attributed to the defendant and which belong to the broader investigative context.
Multinational Investigation Began After the Zurich Attacks
The case stems from an investigation launched after ransomware attacks against Zurich-based companies in 2019. The inquiry later expanded with the involvement of authorities from Switzerland, France, the Netherlands, Norway, Ukraine, and the United States.
The cooperation involved countries connected to infrastructure, victims, suspects, or digital traces distributed across multiple jurisdictions. In operations of this kind, servers, accounts, devices, and financial flows may be located in different countries, requiring mutual legal assistance and coordinated investigative activity.
The defendant has been in custody since October 2021. Prosecutors have also requested his expulsion from Switzerland for 12 years and the forfeiture of CHF 1.8 million, approximately $2.2 million, allegedly derived from criminal activity.
The verdict is expected in September. Until a final decision is issued, the allegations described in the proceedings remain claims by the prosecution and do not constitute a conviction.
Proceedings Also Include Charges Involving Child Sexual Abuse Material
In addition to the ransomware-related offenses, the defendant also faces charges involving child sexual abuse material.
During a search, investigators allegedly found nearly 7,000 images and more than 500 videos depicting child sexual abuse in an encrypted container. Federal Supreme Court documents confirm that these allegations form part of the criminal proceedings.
The material is described only to the extent necessary to convey the scope of the charges. Its presence introduces a separate legal strand, distinct from the ransomware operation and the assessment of the companies’ financial losses.
For organizations defending corporate infrastructure, the case does not identify specific patches, detection tools, technical indicators, or containment procedures. No vulnerable software versions or single attack technique requiring remediation have been disclosed. The matter primarily concerns the judicial attribution of a criminal operation and the reconstruction of individual responsibility.
Sources
This article is an original reworking based on the sources below.
