2026-08-18NOTABLEZurich District Court sentences the Stadler Rail ransomware developer to 12 years 9 months, nine months more than the prosecution itself asked for
Zurich District Court LockerGoga / MegaCortex / Nefilim ransomware trial (2026)
incident · incident:zurich-lockergoga-megacortex-nefilim-trial-2026
Trial opened at Zurich District Court on 2026-08-17 of a 52-year-old Ukrainian software developer resident in canton Basel-Landschaft, in custody since October 2021, charged with commercial extortion, multiple counts of serious data corruption, serious money laundering and possession of child pornography over an international ransomware operation running December 2018 to May 2020. The indictment lists ten victim companies, four of them Swiss, Stadler Rail, Meier Tobler, Crealogix and IHI Ionbond (20 Minuten), with Netzwoche placing the ten across Switzerland, France, Norway, Scotland, Canada, the Netherlands and the United States, with economic damage put by the prosecution above CHF 100 million (20 Minuten) or above CHF 130 million (Netzwoche); three non-Swiss victims paid CHF 4.5 million in ransoms and the Swiss companies paid none. The charge sheet describes the intrusion pattern as obtaining access, switching off monitoring processes, then encrypting servers and workstations including backup files, with roughly 500 GB exfiltrated from Stadler Rail under threat of publication. Prosecutors allege the group's Moscow-based principal operated under a cover identity of Russia's FSB; the defendant contests the charges and no verdict has been reached (cash.ch, 20 Minuten, Netzwoche, 2026-08-17).
Aliases: Stadler Rail ransomware trial
Coverage
1
first 2026-08-18 → last 2026-08-18
Latest activity
2026-09-11
Zurich District Court sentences the Stadler Rail ransomware developer to 12 years 9 months, nine months more…
Peak priority
notable
1 notable
Targets
transport
sectors: transport, finance, manufacturing · regions: switzerland, europe
Sources cited
6
4 hosts
Defender insights
What each entry about Zurich District Court LockerGoga / MegaCortex / Nefilim ransomware trial (2026) tells a defender to do, newest first.
Triage · detection
Relationships explore in graph
Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.
uses
- LockerGoganamed in the Zurich charge sheet as one of the three ransomware families deployed in the prosecuted operation
- MegaCortexnamed in the Zurich charge sheet as one of the three ransomware families deployed in the prosecuted operation
- Nefilimnamed in the Zurich charge sheet as one of the three ransomware families deployed in the prosecuted operation
Story timeline
Hunting pivots
ATT&CK techniques (4 across 2 tactics)
4 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Defense ImpairmentDisable or Modify Tools
- ImpactData Encrypted for Impact · Inhibit System Recovery · Financial Theft
Defense Impairment TA0112
T1685Disable or Modify Tools×1
Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping specific services, killing processes, modifying or deleting tool configuration files and Registry keys, or preventing tools from updating. This may also include impairing defenses more broadly by disrupting preventative, detection, and response mechanisms across host, network, and cloud environments.
Evidence: 2026-08-18/zurich-trial-lockergoga-megacortex-nefilim-swiss-victims · ATT&CK page ↗
Impact TA0040
T1486Data Encrypted for Impact×1
Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources. They can attempt to render stored data inaccessible by encrypting files or data on local and remote drives and withholding access to a decryption key. This may be done in order to extract monetary compensation from a victim in exchange for decryption or a decryption key (ransomware) or to render data permanently inaccessible in cases where the key is not saved or transmitted.
Evidence: 2026-08-18/zurich-trial-lockergoga-megacortex-nefilim-swiss-victims · ATT&CK page ↗
T1490Inhibit System Recovery×1
Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery. This may deny access to available backups and recovery options.
Evidence: 2026-08-18/zurich-trial-lockergoga-megacortex-nefilim-swiss-victims · ATT&CK page ↗
T1657Financial Theft×1
Adversaries may steal monetary resources from targets through extortion, social engineering, technical theft, or other methods aimed at their own financial gain at the expense of the availability of these resources for victims. Financial theft is the ultimate objective of several popular campaign types including extortion by ransomware, business email compromise (BEC) and fraud, "pig butchering," bank hacking, and exploiting cryptocurrency networks.
Evidence: 2026-08-18/zurich-trial-lockergoga-megacortex-nefilim-swiss-victims · ATT&CK page ↗
Entries about Zurich District Court LockerGoga / MegaCortex / Nefilim ransomware trial (2026) (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
Where this entity is cited
Source distribution
- 20min.ch2 (33%)
- cash.ch2 (33%)
- netzwoche.ch1 (17%)
- srf.ch1 (17%)
All cited sources (6)
- 20min.ch20 Minutenhttps://www.20min.ch/story/bezirksgericht-zuerich-ukrainischer-hacker-52-muss-fuer-fast-13-jahre-ins-gefaengnis-103618489
- 20min.ch20 Minutenhttps://www.20min.ch/story/ransomware-angriffe-auf-schweizer-firmen-12-jahre-haft-gefordert-103618489
- cash.chcash.ch (AWP wire)https://www.cash.ch/news/hacker-von-stadler-rail-und-meier-tobler-zu-langer-haft-verurteilt-967811
- cash.chcash.chhttps://www.cash.ch/news/top-news/hacker-steht-nach-attacke-auf-stadler-rail-und-andere-firmen-vor-gericht-961362
- netzwoche.chNetzwochehttps://www.netzwoche.ch/news/2026-08-17/update-mutmasslicher-cyberkrimineller-steht-in-zuerich-vor-gericht
- srf.chSRF (Schweizer Radio und Fernsehen)https://www.srf.ch/news/schweiz/zuercher-bezirksgericht-hackerangriff-auf-stadler-rail-taeter-zu-langer-haft-verurteilt