Two court filings two days apart put Swiss victims on the record — a Zurich indictment over LockerGoga, MegaCortex and Nefilim, and a US superseding indictment against Iran's Mabna Institute — and both describe tradecraft that is still exactly current
Two documents this week name Switzerland in a victim list, and both are charge sheets. That is worth pausing on before the technical content, because it says something about where attribution actually comes from for a European defender: the week's live Swiss incidents — a Valais commune's mailbox, a Zurich business school's student records — name no actor at all beyond an extortion brand's own leak-site listing, while the two documents that do name operations and defendants concern intrusions that ended in 2020 and 2017 respectively.
The Zurich trial. A 52-year-old Ukrainian software developer resident in canton Basel-Landschaft and in custody since October 2021 appeared before Zurich District Court on 2026-08-17, charged in connection with ransomware attacks, and the prosecution seeks twelve years' imprisonment and a twelve-year entry ban (cash.ch, 2026-08-17). Netzwoche puts the charged period at December 2018 to May 2020 and names the three families as LockerGoga, MegaCortex and Nefilim (Netzwoche, 2026-08-19); cash.ch names Lockergoga, Megacortex and a further tool called RMS. The indictment lists ten companies, four of them Swiss — Meier Tobler, Crealogix, IHI Ionbond and Stadler Rail — and records that three victims, none Swiss, paid ransoms totalling CHF 4.5 million while the Swiss companies paid nothing (20 Minuten, 2026-08-17). Prosecutors put economic damage above CHF 100 million, arising from business interruption, delivery delays, work stoppages and the special measures the companies had to mount (20 Minuten, 2026-08-17).
Unusually for court reporting, the operational sequence is in the charge sheet. Per cash.ch's account of the indictment, the group obtained access to the systems, switched off monitoring processes, and then encrypted servers as well as workstations (cash.ch, 2026-08-17); 20 Minuten records the group's stated objective as penetrating as many company networks as possible in Western Europe and North America and encrypting the data including the backup files (20 Minuten, 2026-08-17). At Stadler Rail the defendant is additionally accused of taking around 500 gigabytes of confidential data and threatening to publish it to increase pressure — double extortion, inside the charged period Netzwoche dates to December 2018 to May 2020 (cash.ch, 2026-08-17).
The Mabna indictment. The Department of Justice unsealed a 14-count superseding indictment on 2026-08-18 charging 17 members of the Mabna Institute, an Iran-based company that in its words "since at least 2013, has conducted a coordinated campaign of cyber intrusions into computer systems for 144 U.S.-based universities, 178 foreign universities, at least 42 U.S.-based private sector companies, at least 11 foreign private sector companies, at least five U.S. federal and state government agencies, and at least two non-governmental organizations (NGOs)" (U.S. Department of Justice, 2026-08-18). Nine of the seventeen were charged in 2018; eight are new. Switzerland appears twice in DOJ's own victim breakdown — among the countries hosting the 178 compromised foreign universities, and among the countries hosting the roughly 11 foreign companies whose employee email accounts were compromised, alongside Germany, Italy, Sweden and the United Kingdom (U.S. Department of Justice, 2026-08-18). The tradecraft against universities is stolen credentials used to log into professor accounts and pull research; the newly charged conduct against companies and at least two governmental entities is password spraying, which DOJ says cost victims in excess of $20 million to investigate and remediate.
Why two charge sheets are worth a strategic entry. Not for attribution — neither changes what anyone hunts for tomorrow, and both sets of allegations are untested. They are worth it for two properties that vendor reporting cannot supply. The first is evidentiary standing: the ordering that every ransomware detection strategy is built around — impair defences, then encrypt, and take the backups in the same operation — is here as a prosecution's account of specific attacks on named companies, not as a vendor's characterisation of an intrusion set. That is a different quality of evidence for anyone who has to argue a control budget. The second is the timescale, and it cuts the other way: the Zurich charged period ends in May 2020 and the trial reaches verdict on 2026-09-10; the Mabna university campaign is dated from around 2013 through at least December 2017 and its second wave of defendants is being charged now. Attribution and consequence arrive on a judicial clock measured in years, and the defensive posture that has to work in the meantime cannot be built on it.
ATT&CK mapping
6 techniques mapped from the cited reporting · MITRE ATT&CK v19.2
Initial Access TA0001
T1078Valid Accounts
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
T1566Phishing
Adversaries may send phishing messages to gain access to victim systems. All forms of phishing are electronically delivered social engineering. Phishing can be targeted, known as spearphishing. In spearphishing, a specific individual, company, or industry will be targeted by the adversary. More generally, adversaries can conduct non-targeted phishing, such as in mass malware spam campaigns.
Persistence TA0003
T1078Valid Accounts
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Privilege Escalation TA0004
T1078Valid Accounts
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Stealth TA0005
T1078Valid Accounts
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Defense Impairment TA0112
T1685Disable or Modify Tools
Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping specific services, killing processes, modifying or deleting tool configuration files and Registry keys, or preventing tools from updating. This may also include impairing defenses more broadly by disrupting preventative, detection, and response mechanisms across host, network, and cloud environments.
Credential Access TA0006
T1110.003Brute Force: Password Spraying
Adversaries may use a single or small list of commonly used passwords against many different accounts to attempt to acquire valid account credentials. Password spraying uses one password (e.g. 'Password01'), or a small list of commonly used passwords, that may match the complexity policy of the domain. Logins are attempted with that password against many different accounts on a network to avoid account lockouts that would normally occur when brute forcing a single account with many passwords.
Impact TA0040
T1486Data Encrypted for Impact
Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources. They can attempt to render stored data inaccessible by encrypting files or data on local and remote drives and withholding access to a decryption key. This may be done in order to extract monetary compensation from a victim in exchange for decryption or a decryption key (ransomware) or to render data permanently inaccessible in cases where the key is not saved or transmitted.
T1490Inhibit System Recovery
Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery. This may deny access to available backups and recovery options.
Sources
AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.