CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

Zurich District Court LockerGoga / MegaCortex / Nefilim ransomware trial (2026)

incident · incident:zurich-lockergoga-megacortex-nefilim-trial-2026

Trial opened at Zurich District Court on 2026-08-17 of a 52-year-old Ukrainian software developer resident in canton Basel-Landschaft, in custody since October 2021, charged with commercial extortion, multiple counts of serious data corruption, serious money laundering and possession of child pornography over an international ransomware operation running December 2018 to May 2020. The indictment lists ten victim companies, four of them Swiss, Stadler Rail, Meier Tobler, Crealogix and IHI Ionbond (20 Minuten), with Netzwoche placing the ten across Switzerland, France, Norway, Scotland, Canada, the Netherlands and the United States, with economic damage put by the prosecution above CHF 100 million (20 Minuten) or above CHF 130 million (Netzwoche); three non-Swiss victims paid CHF 4.5 million in ransoms and the Swiss companies paid none. The charge sheet describes the intrusion pattern as obtaining access, switching off monitoring processes, then encrypting servers and workstations including backup files, with roughly 500 GB exfiltrated from Stadler Rail under threat of publication. Prosecutors allege the group's Moscow-based principal operated under a cover identity of Russia's FSB; the defendant contests the charges and no verdict has been reached (cash.ch, 20 Minuten, Netzwoche, 2026-08-17).

Aliases: Stadler Rail ransomware trial

Coverage
1
first 2026-08-18 → last 2026-08-18
Latest activity
2026-09-11
Zurich District Court sentences the Stadler Rail ransomware developer to 12 years 9 months, nine months more…
Peak priority
notable
1 notable
Targets
transport
sectors: transport, finance, manufacturing · regions: switzerland, europe
Sources cited
6
4 hosts

Defender insights

What each entry about Zurich District Court LockerGoga / MegaCortex / Nefilim ransomware trial (2026) tells a defender to do, newest first.

2026-08-18NOTABLEZurich District Court sentences the Stadler Rail ransomware developer to 12 years 9 months, nine months more than the prosecution itself asked for

Triage · detection

Relationships explore in graph

Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.

uses

Story timeline

  1. 2026-08-18Zurich District Court opens the LockerGoga / MegaCortex / Nefilim trial: four named Swiss victims, CHF 100m+ in damage, and an indictment that describes the intrusion pattern step by step
    active-threatsZurich District Court sentences the Stadler Rail ransomware developer to 12 years 9 months, nine months more than the prosecution itself asked for
ATT&CK techniques (4 across 2 tactics)

4 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • Defense ImpairmentDisable or Modify Tools
  • ImpactData Encrypted for Impact · Inhibit System Recovery · Financial Theft

Defense Impairment TA0112

T1685Disable or Modify Tools×1

Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping specific services, killing processes, modifying or deleting tool configuration files and Registry keys, or preventing tools from updating. This may also include impairing defenses more broadly by disrupting preventative, detection, and response mechanisms across host, network, and cloud environments.

Evidence: 2026-08-18/zurich-trial-lockergoga-megacortex-nefilim-swiss-victims · ATT&CK page ↗

Impact TA0040

T1486Data Encrypted for Impact×1

Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources. They can attempt to render stored data inaccessible by encrypting files or data on local and remote drives and withholding access to a decryption key. This may be done in order to extract monetary compensation from a victim in exchange for decryption or a decryption key (ransomware) or to render data permanently inaccessible in cases where the key is not saved or transmitted.

Evidence: 2026-08-18/zurich-trial-lockergoga-megacortex-nefilim-swiss-victims · ATT&CK page ↗

T1490Inhibit System Recovery×1

Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery. This may deny access to available backups and recovery options.

Evidence: 2026-08-18/zurich-trial-lockergoga-megacortex-nefilim-swiss-victims · ATT&CK page ↗

T1657Financial Theft×1

Adversaries may steal monetary resources from targets through extortion, social engineering, technical theft, or other methods aimed at their own financial gain at the expense of the availability of these resources for victims. Financial theft is the ultimate objective of several popular campaign types including extortion by ransomware, business email compromise (BEC) and fraud, "pig butchering," bank hacking, and exploiting cryptocurrency networks.

Evidence: 2026-08-18/zurich-trial-lockergoga-megacortex-nefilim-swiss-victims · ATT&CK page ↗

Entries about Zurich District Court LockerGoga / MegaCortex / Nefilim ransomware trial (2026) (1)

2026-08-18 · view entry permalink →

NOTABLEupdatedNATOB2

Zurich District Court opens the LockerGoga / MegaCortex / Nefilim trial: four named Swiss victims, CHF 100m+ in damage, and an indictment that describes the intrusion pattern step by step

A 52-year-old Ukrainian software developer, resident in canton Basel-Landschaft and in custody since October 2021, appeared before Zurich District Court on 2026-08-17 charged with commercial extortion, multiple counts of serious data corruption, serious money laundering and possession of child pornography (cash.ch, 2026-08-17). The charge sheet covers attacks between December 2018 and May 2020 involving the ransomware families LockerGoga, MegaCortex and Nefilim (Netzwoche, 2026-08-17); the proceedings were triggered by a series of ransomware attacks on Zurich-area companies from July 2019. Per the indictment as reported by cash.ch, the defendant developed LockerGoga largely independently on the instruction of a co-accused in Moscow, later contributed to MegaCortex, and took a leading role as project manager on a further tool (cash.ch, 2026-08-17). The prosecution seeks twelve years' imprisonment and a twelve-year entry ban (cash.ch, 2026-08-17).

The indictment lists ten companies, four of them Swiss: Meier Tobler, Crealogix, IHI Ionbond and Stadler Rail (20 Minuten, 2026-08-17). Netzwoche reports the defendant is alleged to have taken part, from his residence in Switzerland, in attacks on ten companies in Switzerland, France, Norway, Scotland, Canada, the Netherlands and the United States (Netzwoche, 2026-08-17). Three victims, none Swiss, paid ransoms totalling CHF 4.5 million; the Swiss companies paid nothing (20 Minuten, 2026-08-17). Netzwoche reports the same proceedings differently, putting the single largest payment at 450 bitcoin, which it values at roughly CHF 41 million at today's rate (Netzwoche, 2026-08-17). The two franc figures are not measuring the same thing: one is what was paid at the time, the other is what that bitcoin is worth now, and neither outlet reconciles them. Prosecutors put the economic damage above CHF 100 million, from business interruptions, delivery delays, work stoppages and the special measures the companies had to mount (20 Minuten, 2026-08-17); Netzwoche reports the prosecution figure as above CHF 130 million, arising mainly from revenue lost to business interruption and the cost of restoring IT systems (Netzwoche, 2026-08-17). Per the indictment as reported by 20 Minuten, the defendant joined with a Ukrainian principal based in Moscow in June 2018, and that principal is alleged to have operated under a cover identity of Russia's FSB; an allegation the prosecution makes in a trial the defendant contests, and one no investigating authority has published independently.

What the charge sheet describes operationally. Unusually for court reporting, the intrusion pattern is spelled out: "Sie verschafften sich Zugang zu den Systemen, schalteten Überwachungsprozesse ab und verschlüsselten anschliessend Server sowie Arbeitsplatzrechner", they obtained access to the systems, switched off monitoring processes, and then encrypted servers as well as workstations (cash.ch, 2026-08-17). 20 Minuten records the group's stated objective as penetrating as many company networks as possible in Western Europe and North America and encrypting "die Daten inklusive Back-up-Dateien", the data including the backup files (20 Minuten, 2026-08-17). At Stadler Rail the defendant is additionally accused of taking around 500 gigabytes of confidential data and threatening to publish it to increase pressure (cash.ch, 2026-08-17), double extortion, inside a charged period Netzwoche reports as December 2018 to May 2020 (Netzwoche, 2026-08-17); no cited source dates that exfiltration more precisely than the period as a whole. The extortion notes claimed the data was encrypted with military-grade algorithms and that any third-party recovery attempt would destroy it (20 Minuten, 2026-08-17), a pressure device rather than a technical fact.

Detection, telemetry class first. Nothing here is a new technique, and the value is not novelty: it is that a court record independently corroborates the ordering that ransomware detection is built around. Defence-impairment precedes encryption, so the telemetry that matters arrives before any file changes, security service and agent stop or configuration-change events, sudden gaps in endpoint agent check-ins across multiple hosts, and audit or logging services terminating outside a maintenance window. Backup infrastructure is a target in the same operation rather than a recovery path afterwards, so authentication and deletion activity against backup catalogues and repositories belongs in the same alerting tier as domain controllers. Triage: legitimate maintenance also stops security agents and touches backup stores; the discriminators are that maintenance is scoped to a change window and a host set, is performed by accounts that routinely do it, and does not spread to servers and workstations at once; a monitoring-process stop that fans out across both populations within a short window, from an account with no history of that action, is the sequence worth waking someone for.

Sie verschafften sich Zugang zu den Systemen, schalteten Überwachungsprozesse ab und verschlüsselten anschliessend Server sowie Arbeitsplatzrechner.

Beim Angriff auf Stadler Rail entwendete der Beschuldigte zudem rund 500 Gigabyte an vertraulichen Daten.

cash.ch 2026-08-17

die Daten inklusive Back-up-Dateien zu verschlüsseln

20 Minuten 2026-08-17

Nach Angaben der Staatsanwaltschaft belaufen sich die wirtschaftlichen Schäden der Angriffe auf über 130 Millionen Franken.

Netzwoche 2026-08-17

Das Zürcher Bezirksgericht hat einen 52-jährigen ukrainischen Hacker zu einer Freiheitsstrafe von 12 Jahren und 9 Monaten und zu einem Landesverweis von 10 Jahren verurteilt.

SRF

Mit seinem Urteil ging das Bezirksgericht sogar noch weiter, als die Staatsanwaltschaft beantragt hatte. Gemäss Anklage sollte der Hacker «nur» zwölf Jahre Freiheitsstrafe erhalten - jetzt werden es neun Monate mehr.

cash.ch (AWP wire) 2026-09-10

Zudem wird er für zehn Jahre des Landes verwiesen und muss 300'000 Franken dem Staat abliefern. Für das Gericht war er der Erpressung, der versuchten Erpressung, der schweren Datenbeschädigung und der Pornografie schuldig.

20 Minuten 2026-08-17

Es gab jedoch keine Hinweise darauf, dass der 52-jährige Mann aus dem Baselbiet selbst Verbindungen zu russischen Geheimdiensten besessen habe.

cash.ch (AWP wire) 2026-09-10
Updaterun 2026-09-11T0410Z-intelheadlinesummarysourcing_notebodysourcesevidence

Zurich District Court delivered its verdict on 2026-09-10: 12 years 9 months' imprisonment and a 10-year expulsion order (SRF, 2026-09-10), an unconditional (non-suspended) sentence (20 Minuten, 2026-09-10), plus forfeiture of CHF 300,000 to the state (20 Minuten, 2026-09-10), nine months more than the prosecution's own 12-year demand (cash.ch, 2026-09-10). The court found the defendant guilty of extortion, attempted extortion, serious data damage and possession of child-sexual-abuse material found on his devices (20 Minuten, 2026-09-10); it rejected his defense that he was an unwitting IT consultant, citing ransom notes (SRF, 2026-09-10) and a body of digital traces found on his own storage media (20 Minuten, 2026-09-10), and it dismissed his bid to have all seized digital evidence ruled inadmissible for want of adequate notice of his data-sealing rights during the searches (cash.ch, 2026-09-10). The judge noted his frequent invocation of the right to silence undermined his credibility (20 Minuten, 2026-09-10), and observed "he was not a mastermind" (translated from German) while finding it proven that he developed the ransomware and passed it to still-unidentified operators who selected victims and coordinated the extortion (SRF, 2026-09-10), a professional effort the judge said spanned three years (20 Minuten, 2026-09-10). The prosecutor's closing argument repeated the contested claim that the group's Moscow-based principal, Oleksandr Ieremenko, held an FSB cover identity and was the subject of a US Secret Service bounty (20 Minuten, 2026-09-10); the court found no evidence that the convicted defendant himself had intelligence-service ties (cash.ch, 2026-09-10). The verdict is not final, the defendant, in security detention throughout, can still appeal to the cantonal Obergericht and the Bundesgericht (SRF, 2026-09-10).

incident18 Aug 04:50Zmulti-sourceOpen finding →

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Where this entity is cited

  • Threats1

Source distribution

  • 20min.ch2 (33%)
  • cash.ch2 (33%)
  • netzwoche.ch1 (17%)
  • srf.ch1 (17%)