Swiss Court Jails Ransomware Coder 12 Years
A Zurich court found the 52-year-old Ukrainian developer built LockerGoga, MegaCortex, and Nefilim, though not as the operations' mastermind.
A 52-year-old Ukrainian developer will spend the next decade-plus of his life in a Swiss prison for writing the code behind three ransomware families that menaced industrial and software companies across Europe. Zurich District Court handed down a sentence of 12 years and nine months and a ten-year ban from Switzerland, according to SWI. The ruling is not final and can be appealed.
The judgment closes one chapter of a case that began with an arrest in Basel-Landschaft in October 2021 and has kept the defendant in pretrial detention ever since. He has denied knowing his software was being used for criminal purposes.
The Code Behind Three Ransomware Families
The court found the man developed LockerGoga, MegaCortex, and Nefilim, three ransomware strains that circulated in overlapping waves. He was not, according to the judges, the person orchestrating the extortion campaigns themselves. That distinction — coder rather than mastermind — did not spare him a lengthy sentence.
His defense rested on the claim that source code found at his home was the product of consulting work for an unidentified IT security client. The court rejected that explanation. Investigators also recovered extortion messages among his data, a detail first reported by SWI, which undercut the consulting-work defense.
A Denial the Court Did Not Buy
Throughout the proceedings, the defendant maintained he had no idea his software was being weaponized. The presence of ransom notes alongside the source code gave the court a different picture — one of a developer whose work product was inseparable from the extortion machinery it powered.
The verdict also tied him to specific intrusions. Zurich District Court found he played a key role in the attack on rolling stock manufacturer Stadler Rail, as well as breaches at HVAC company Meier Tobler and software company Crealogix.
Stadler Rail and the $6 Million Demand
The Stadler Rail incident occurred in May 2020, distinct from a more recent attack on the same manufacturer that was claimed by Everest. At the time, Stadler did not use the word ransomware. The company said the attack involved malware, that it most likely led to a data leak, and that the offenders tried to extort a large amount of money, threatening to leak files if the ransom was not paid. The Nefilim ransom demand was reportedly $6 million. Stadler refused to pay, as it also did following the later incident.
The scale of the broader operation came into focus in September 2022, when Zurich prosecutors disclosed that a suspect had been arrested in Basel-Landschaft in October 2021 on suspicion of money laundering and data corruption. That statement accused the perpetrators of involvement in attacks on more than 1,800 individuals and institutions across 71 countries, with estimated losses of several hundred million Swiss francs.
A Mastermind Still at Large
The same 2021 law enforcement action led to the identification of other alleged members of the three ransomware operations, none of whom were named. One figure stands apart: Volodymyr Tymoshchuk, formally indicted in the US last year and described by prosecutors as the mastermind of all three crews. He has not been arrested and remains on the FBI's most wanted list, with an $11 million bounty for information leading to his arrest or conviction, or that of other key leaders. He was allegedly responsible for attacks on at least 250 companies, including the Norsk Hydro attack in 2019.
The Swiss case, then, resolves the question of who wrote the tools without resolving who directed them. That gap between coder and commander runs through the verdict: the court accepted the defendant's technical role but rejected his claim of ignorance.
What the Sentence Actually Signals
Switzerland is not a jurisdiction known for throwing away the key on cybercrime cases, which makes the nearly 13-year term notable. The ten-year entry ban adds a second layer of separation between the defendant and the country where he was arrested and tried.
For defenders at industrial and software firms, the case offers a reminder that the ransomware ecosystem has specialized roles. The person who writes the encryptor is not necessarily the person who negotiates, launders proceeds, or selects targets. Prosecutors pursuing the full chain have to work through each layer separately — and in this instance, the top layer remains beyond reach.
The Numbers Behind the Case
- 12 years and nine months — prison sentence handed down by Zurich District Court
- 10 years — ban from Switzerland accompanying the sentence
- October 2021 — arrest in Basel-Landschaft; pretrial detention has continued since
- $6 million — reported Nefilim ransom demand against Stadler Rail in 2020
- 1,800+ — individuals and institutions targeted across 71 countries, per September 2022 prosecutors' statement
- $11 million — FBI bounty for information on Volodymyr Tymoshchuk
- 250+ — companies Tymoshchuk allegedly targeted, including Norsk Hydro in 2019
Why It Matters Beyond the Courtroom
The verdict suggests that writing ransomware code can carry consequences as severe as running the operation — at least in a Swiss court willing to impose a sentence measured in years rather than months. For businesses, the more durable takeaway is structural: the arrest of one developer does not dismantle the crews that used his tools. LockerGoga, MegaCortex, and Nefilim may be dormant or rebranded, but the people who directed those campaigns, by prosecutors' own account, remain at large.
That asymmetry — a coder in a Swiss cell, an alleged mastermind on an FBI poster — is the uncomfortable shape of ransomware accountability in 2026. The defendant's appeal, should he pursue it, will test whether the court's reading of his intent holds up. For now, the judgment stands as a data point: a single developer, three ransomware families, and nearly 13 years.
Sources
- The Register Original source
- SWI Also reporting
Continue Reading
Malware Taps MQTT to Run Windows, Linux Bots
Lumen's Black Lotus Labs says BambooToken abuses the IoT messaging protocol and a signed banking token to control compromised hosts across Asia and South America.
Fake Hires Get Network Access First
A HYPR report finds most fraudulent hires receive corporate credentials before detection, leaving firms exposed to insider risk.
Ransomware Recovery Plans Fail in Practice
Fenix24's first State of Recoverability report finds only four of more than 800 clients neared their own recovery targets after a ransomware attack.