2026-08-18NOTABLEZurich District Court sentences the Stadler Rail ransomware developer to 12 years 9 months, nine months more than the prosecution itself asked for
Nefilim
malware · malware:nefilim
Ransomware family named in the Zurich District Court charge sheet alongside LockerGoga and MegaCortex for the December 2018 to May 2020 extortion operation prosecuted from 2026-08-17. The charge sheet attributes cyberattacks using all three families to the accused; no source in this run's reporting separates which victims received which family (Netzwoche, 2026-08-17).
Coverage
1
first 2026-08-18 → last 2026-08-18
Latest activity
2026-09-11
Zurich District Court sentences the Stadler Rail ransomware developer to 12 years 9 months, nine months more…
Peak priority
notable
1 notable
Targets
transport
sectors: transport, finance, manufacturing · regions: switzerland, europe
Sources cited
6
4 hosts
Defender insights
What each entry about Nefilim tells a defender to do, newest first.
Triage · detection
Relationships explore in graph
Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.
used by
- Zurich District Court LockerGoga / MegaCortex / Nefilim ransomware trial (2026)named in the Zurich charge sheet as one of the three ransomware families deployed in the prosecuted operation
Story timeline
Hunting pivots
ATT&CK techniques (4 across 2 tactics)
4 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Defense ImpairmentDisable or Modify Tools
- ImpactData Encrypted for Impact · Inhibit System Recovery · Financial Theft
Defense Impairment TA0112
T1685Disable or Modify Tools×1
Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping specific services, killing processes, modifying or deleting tool configuration files and Registry keys, or preventing tools from updating. This may also include impairing defenses more broadly by disrupting preventative, detection, and response mechanisms across host, network, and cloud environments.
Evidence: 2026-08-18/zurich-trial-lockergoga-megacortex-nefilim-swiss-victims · ATT&CK page ↗
Impact TA0040
T1486Data Encrypted for Impact×1
Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources. They can attempt to render stored data inaccessible by encrypting files or data on local and remote drives and withholding access to a decryption key. This may be done in order to extract monetary compensation from a victim in exchange for decryption or a decryption key (ransomware) or to render data permanently inaccessible in cases where the key is not saved or transmitted.
Evidence: 2026-08-18/zurich-trial-lockergoga-megacortex-nefilim-swiss-victims · ATT&CK page ↗
T1490Inhibit System Recovery×1
Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery. This may deny access to available backups and recovery options.
Evidence: 2026-08-18/zurich-trial-lockergoga-megacortex-nefilim-swiss-victims · ATT&CK page ↗
T1657Financial Theft×1
Adversaries may steal monetary resources from targets through extortion, social engineering, technical theft, or other methods aimed at their own financial gain at the expense of the availability of these resources for victims. Financial theft is the ultimate objective of several popular campaign types including extortion by ransomware, business email compromise (BEC) and fraud, "pig butchering," bank hacking, and exploiting cryptocurrency networks.
Evidence: 2026-08-18/zurich-trial-lockergoga-megacortex-nefilim-swiss-victims · ATT&CK page ↗
Entries about Nefilim (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
- LockerGoga×1
- MegaCortex×1
- Zurich District Court LockerGoga / MegaCortex / Nefilim ransomware trial (2026)×1
Where this entity is cited
Source distribution
- 20min.ch2 (33%)
- cash.ch2 (33%)
- netzwoche.ch1 (17%)
- srf.ch1 (17%)
All cited sources (6)
- 20min.ch20 Minutenhttps://www.20min.ch/story/bezirksgericht-zuerich-ukrainischer-hacker-52-muss-fuer-fast-13-jahre-ins-gefaengnis-103618489
- 20min.ch20 Minutenhttps://www.20min.ch/story/ransomware-angriffe-auf-schweizer-firmen-12-jahre-haft-gefordert-103618489
- cash.chcash.ch (AWP wire)https://www.cash.ch/news/hacker-von-stadler-rail-und-meier-tobler-zu-langer-haft-verurteilt-967811
- cash.chcash.chhttps://www.cash.ch/news/top-news/hacker-steht-nach-attacke-auf-stadler-rail-und-andere-firmen-vor-gericht-961362
- netzwoche.chNetzwochehttps://www.netzwoche.ch/news/2026-08-17/update-mutmasslicher-cyberkrimineller-steht-in-zuerich-vor-gericht
- srf.chSRF (Schweizer Radio und Fernsehen)https://www.srf.ch/news/schweiz/zuercher-bezirksgericht-hackerangriff-auf-stadler-rail-taeter-zu-langer-haft-verurteilt