2026-08-18 · view entry permalink →
Zurich District Court opens the LockerGoga / MegaCortex / Nefilim trial: four named Swiss victims, CHF 100m+ in damage, and an indictment that describes the intrusion pattern step by step
A 52-year-old Ukrainian software developer, resident in canton Basel-Landschaft and in custody since October 2021, appeared before Zurich District Court on 2026-08-17 charged with commercial extortion, multiple counts of serious data corruption, serious money laundering and possession of child pornography (cash.ch, 2026-08-17). The charge sheet covers attacks between December 2018 and May 2020 involving the ransomware families LockerGoga, MegaCortex and Nefilim (Netzwoche, 2026-08-17); the proceedings were triggered by a series of ransomware attacks on Zurich-area companies from July 2019. Per the indictment as reported by cash.ch, the defendant developed LockerGoga largely independently on the instruction of a co-accused in Moscow, later contributed to MegaCortex, and took a leading role as project manager on a further tool (cash.ch, 2026-08-17). The prosecution seeks twelve years' imprisonment and a twelve-year entry ban (cash.ch, 2026-08-17).
The indictment lists ten companies, four of them Swiss: Meier Tobler, Crealogix, IHI Ionbond and Stadler Rail (20 Minuten, 2026-08-17). Netzwoche reports the defendant is alleged to have taken part, from his residence in Switzerland, in attacks on ten companies in Switzerland, France, Norway, Scotland, Canada, the Netherlands and the United States (Netzwoche, 2026-08-17). Three victims, none Swiss, paid ransoms totalling CHF 4.5 million; the Swiss companies paid nothing (20 Minuten, 2026-08-17). Netzwoche reports the same proceedings differently, putting the single largest payment at 450 bitcoin, which it values at roughly CHF 41 million at today's rate (Netzwoche, 2026-08-17). The two franc figures are not measuring the same thing: one is what was paid at the time, the other is what that bitcoin is worth now, and neither outlet reconciles them. Prosecutors put the economic damage above CHF 100 million, from business interruptions, delivery delays, work stoppages and the special measures the companies had to mount (20 Minuten, 2026-08-17); Netzwoche reports the prosecution figure as above CHF 130 million, arising mainly from revenue lost to business interruption and the cost of restoring IT systems (Netzwoche, 2026-08-17). Per the indictment as reported by 20 Minuten, the defendant joined with a Ukrainian principal based in Moscow in June 2018, and that principal is alleged to have operated under a cover identity of Russia's FSB — an allegation the prosecution makes in a trial the defendant contests, and one no investigating authority has published independently.
What the charge sheet describes operationally. Unusually for court reporting, the intrusion pattern is spelled out: "Sie verschafften sich Zugang zu den Systemen, schalteten Überwachungsprozesse ab und verschlüsselten anschliessend Server sowie Arbeitsplatzrechner" — they obtained access to the systems, switched off monitoring processes, and then encrypted servers as well as workstations (cash.ch, 2026-08-17). 20 Minuten records the group's stated objective as penetrating as many company networks as possible in Western Europe and North America and encrypting "die Daten inklusive Back-up-Dateien" — the data including the backup files (20 Minuten, 2026-08-17). At Stadler Rail the defendant is additionally accused of taking around 500 gigabytes of confidential data and threatening to publish it to increase pressure (cash.ch, 2026-08-17) — double extortion, inside a charged period Netzwoche reports as December 2018 to May 2020 (Netzwoche, 2026-08-17); no cited source dates that exfiltration more precisely than the period as a whole. The extortion notes claimed the data was encrypted with military-grade algorithms and that any third-party recovery attempt would destroy it (20 Minuten, 2026-08-17) — a pressure device rather than a technical fact.
Detection, telemetry class first. Nothing here is a new technique, and the value is not novelty: it is that a court record independently corroborates the ordering that ransomware detection is built around. Defence-impairment precedes encryption, so the telemetry that matters arrives before any file changes — security service and agent stop or configuration-change events, sudden gaps in endpoint agent check-ins across multiple hosts, and audit or logging services terminating outside a maintenance window. Backup infrastructure is a target in the same operation rather than a recovery path afterwards, so authentication and deletion activity against backup catalogues and repositories belongs in the same alerting tier as domain controllers. Triage: legitimate maintenance also stops security agents and touches backup stores — the discriminators are that maintenance is scoped to a change window and a host set, is performed by accounts that routinely do it, and does not spread to servers and workstations at once; a monitoring-process stop that fans out across both populations within a short window, from an account with no history of that action, is the sequence worth waking someone for.
Sie verschafften sich Zugang zu den Systemen, schalteten Überwachungsprozesse ab und verschlüsselten anschliessend Server sowie Arbeitsplatzrechner.
Beim Angriff auf Stadler Rail entwendete der Beschuldigte zudem rund 500 Gigabyte an vertraulichen Daten.
die Daten inklusive Back-up-Dateien zu verschlüsseln
Nach Angaben der Staatsanwaltschaft belaufen sich die wirtschaftlichen Schäden der Angriffe auf über 130 Millionen Franken.