Zurich court jails Ukrainian ransomware developer for 13 years

A landmark Swiss verdict holds a ransomware code writer accountable for $123 million in damages across three major malware families.

By Central
The Zurich court convicted the lead developer of LockerGoga, MegaCortex, and Nefilim ransomware, setting a precedent for software liability.
Highlights
  • The Ukrainian developer was sentenced to 12 years and 9 months in prison for creating three ransomware families.
  • The ransomware strains caused an estimated 100 million Swiss francs ($123 million) in damages to global organizations.
  • The court rejected the defendant's claim that he was unaware his software was used for criminal extortion.

A court in Zurich has sentenced a 52-year-old Ukrainian national to 12 years and nine months in prison, alongside a 10-year ban from Switzerland, after finding him to be the principal developer behind three of the most disruptive ransomware families to have targeted global enterprises in recent years. The verdict, handed down by a Swiss criminal court, marks one of the most significant legal actions taken against a ransomware architect rather than a distributor or extortionist, and it sends a clear signal that writing the code that enables digital extortion carries severe criminal liability, even when the developer attempts to distance himself from how that code is ultimately deployed. The man, who had been residing in the Basel-Landschaft region and has not been publicly named under Swiss reporting conventions, was convicted for his role in creating the LockerGoga, MegaCortex, and Nefilim ransomware strains, which together caused an estimated 100 million Swiss francs (approximately $123 million) in damages to organizations across multiple continents.

A Landmark Sentence in Swiss Cybercrime Jurisprudence

The prison term, calculated at 12 years and nine months, reflects the court’s assessment of the defendant’s central role in the development of malware that brought major industrial operations to a halt. Swiss prosecutors built their case around the contention that the man was not merely a peripheral contributor but the lead developer who wrote the core code for all three ransomware families, a claim the court upheld after examining digital evidence, source code repositories, and communications linking him to the malware’s creation. The 10-year expulsion order bars him from re-entering Switzerland for a decade following his release, a penalty that underscores the seriousness with which Swiss authorities treat cybercrime that targets infrastructure and industry, even when the perpetrator is not the one directly launching attacks or issuing ransom demands. Legal experts have noted that this sentencing establishes an important precedent in Swiss law, demonstrating that the judiciary is prepared to hold software developers accountable for the downstream consequences of their work when they know, or should have known, that their creations would be used for criminal purposes.

Writing the code that enables digital extortion carries severe criminal liability, even when the developer attempts to distance himself from how that code is ultimately deployed.

The Developer’s Defense and the Court’s Rejection

Throughout the proceedings, the Ukrainian man maintained that he was unaware his software was being used for criminal extortion, a defense that has become increasingly common in cybercrime prosecutions around the world. He claimed that the presence of the ransomware source code on his personal devices was explained by his work as a cybersecurity consultant for an unnamed client, arguing that his role involved analyzing malware, not creating it for illicit use. The court, however, was not persuaded. Judges examined the totality of evidence, including the structure of the code, the patterns of updates and version releases, and the defendant’s technical expertise, and concluded that his claims of ignorance were not credible. The ruling makes clear that, in the view of the Swiss justice system, a developer who builds a weapon and supplies it to others with the expectation that it will be used to cause harm cannot escape liability simply by claiming not to have pulled the trigger. This legal reasoning aligns with broader international trends in cybercrime prosecution, where authorities increasingly target the entire supply chain of ransomware operations, from developers and initial access brokers to money launderers and negotiators.

LockerGoga, MegaCortex, and Nefilim: A Trilogy of Destruction

The three ransomware families at the heart of this case share a common architectural lineage and a history of targeting large, high-value industrial and manufacturing organizations. LockerGoga, first observed in early 2019, gained widespread notoriety when it crippled the operations of Norwegian aluminium giant Norsk Hydro, forcing the company to shut down its global network and revert to manual operations at multiple smelting plants. That attack, which ultimately cost Norsk Hydro tens of millions of dollars in lost production and remediation, became a landmark case study in industrial cybersecurity, demonstrating how ransomware could disrupt not just IT systems but physical industrial processes. MegaCortex, which emerged later that same year, employed a sophisticated multi-stage infection chain and was often deployed alongside other trojans such as IcedID and Cobalt Strike, reflecting an evolution in the operational maturity of the ransomware groups behind it. Nefilim, which appeared in 2020, introduced a data theft component as a secondary extortion mechanism, threatening to publish stolen confidential information if victims refused to pay, a tactic that has since become standard in the ransomware ecosystem. The court found that the defendant was the common technical thread linking all three families, having developed the foundational code that each group then customized and deployed.

High-Profile Victims and the Scale of the Damage

Beyond Norsk Hydro, the victims of these ransomware strains include organizations of significant strategic and economic importance. Stadler Rail, a Swiss train manufacturer, suffered an attack in 2020 that resulted in the theft of approximately 500 GB of confidential corporate data. The company ultimately refused to pay the reported $6 million ransom demand, a decision that, while principled, left it facing the operational and reputational consequences of a major data breach. Chemical companies Hexion and Momentive were also targeted, with their operations disrupted to varying degrees. Prosecutors aggregated the damages across all known victims to arrive at the 100 million Swiss franc figure, though the true economic impact, including downtime, recovery costs, and lost business, is likely substantially higher. These attacks did not occur in isolation but were part of a broader wave of ransomware activity that targeted manufacturing, energy, and critical infrastructure sectors globally between 2019 and 2021, a period widely regarded as the peak of the first major ransomware pandemic.

The United States Investigation and the Tymoshchuk Connection

The Swiss case runs in parallel with a separate criminal investigation underway in the United States, where prosecutors have unsealed charges against Volodymyr Tymoshchuk, a Ukrainian national identified as an administrator of the same ransomware families. The US Department of Justice indictment alleges that Tymoshchuk played a managerial role in the LockerGoga, MegaCortex, and Nefilim operations, overseeing their deployment and managing the ransom payment infrastructure. The US State Department has offered rewards of up to $11 million for information leading to the arrest or conviction of Tymoshchuk and his associates, a figure that reflects the high priority US law enforcement places on dismantling the leadership of these ransomware groups. While the developer convicted in Zurich appears to have been the builder of the malware rather than its operator, the charges against Tymoshchuk target the organizational and administrative layer of the same criminal enterprise. Together, the Swiss verdict and the US indictment represent a coordinated, multi-jurisdictional effort to hold accountable every level of the ransomware hierarchy, from the person who wrote the code to the person who managed the business operations.

The Distinction Between Developer and Operator in Criminal Law

The Zurich court’s decision to treat the developer as criminally liable, despite his lack of direct involvement in the extortion campaigns, is legally significant. In many ransomware cases, the individuals who deploy the malware and negotiate with victims are the ones who face prosecution, while the developers argue that they are merely software engineers whose work was misused by others. This case challenges that framing, establishing that a developer who creates a tool with the clear purpose of facilitating crime, and who knows or can reasonably foresee that it will be used for that purpose, bears moral and legal responsibility for the resulting harm. The court appears to have drawn a line, however, between building the malware and directing its use, which may explain why the sentence, while severe, did not approach the maximum penalties available. This distinction will be closely watched by cybersecurity professionals and legal analysts, as it could influence how future cases are charged and how defendants structure their defenses. The verdict also raises questions about the liability of developers who create penetration testing tools, remote access software, or other dual-use technologies that can be employed for both legitimate security work and malicious attacks.

A Free Decryptor for LockerGoga Victims

For organizations and individuals who fell victim to LockerGoga and have not yet recovered their data, there is a potentially significant development emerging from this case. In 2022, cybersecurity firm Bitdefender released a universal decryptor for LockerGoga, developed in cooperation with law enforcement agencies. The decryptor was made available at no cost, providing a path for victims to restore their encrypted files without paying a ransom to the criminals. The release of the decryptor followed technical analysis of the encryption algorithms used in LockerGoga, which revealed weaknesses that could be exploited to reverse the encryption without the attacker’s private key. This is a reminder that the forensic analysis of ransomware can sometimes yield decryptors even years after the initial attacks, and that organizations that preserved encrypted samples without paying ransoms may still have options. The availability of the decryptor also underscores the importance of reporting ransomware attacks to law enforcement, as such reports often provide the raw material that security researchers and authorities need to develop technical countermeasures.

What the Zurich Verdict Means for the Ransomware Ecosystem

The conviction of a ransomware developer in a European court and the parallel US investigation into an alleged administrator of the same operations represent meaningful progress in the global fight against ransomware, but the practical impact on the broader ecosystem should be assessed carefully. Ransomware is not a monolithic industry but a distributed, modular network of actors who specialize in different functions, and the removal of any single individual, even a significant developer or administrator, does not dismantle the entire enterprise. The LockerGoga, MegaCortex, and Nefilim strains have already largely faded from active deployment, having been supplanted by newer families such as LockBit, BlackCat (ALPHV), and others that incorporate lessons learned from earlier operations. The code and techniques developed by the convicted developer have likely been absorbed into the collective knowledge base of the ransomware community, where they continue to influence the design of new malware. Nevertheless, the legal precedent set in Zurich matters. It signals to developers that writing ransomware code carries personal legal risk, regardless of whether they personally operate the malware, and it provides prosecutors in other jurisdictions with a template for building cases against technical contributors.

The 12-year and nine-month sentence is also a deterrent, albeit one whose effectiveness will depend on whether would-be ransomware developers believe they will be caught. Many of the most prolific ransomware developers operate out of jurisdictions where law enforcement capacity is limited or where extradition treaties are weak, reducing the practical risk of prosecution. The Ukrainian man in this case was living in Switzerland, a country with robust law enforcement and judicial systems, and his arrest followed what was likely a lengthy investigation involving international cooperation. Developers who remain in countries with less effective cybercrime enforcement, or who take precautions to obscure their identities and locations, may not be as easily reached. The verdict, therefore, is likely to have its strongest deterrent effect on individuals who are considering operating from within Western Europe or other regions with strong rule of law, rather than on those who are already embedded in jurisdictions where they feel immune from prosecution.

Lessons for Organizations: The Practical Takeaways

For corporate security teams and executives, the Zurich case offers several actionable insights. First, the fact that the Swiss court focused on the developer rather than the deployers reinforces the importance of tracing ransomware attacks back to their technical origins, which requires detailed forensic analysis, threat intelligence sharing, and cooperation with law enforcement. Organizations that invest in incident response capabilities and maintain relationships with law enforcement agencies are better positioned to contribute to investigations that may ultimately lead to arrests and convictions. Second, the availability of the LockerGoga decryptor demonstrates that data encrypted by older ransomware strains may not be permanently lost, and that maintaining encrypted backups and samples, rather than immediately formatting infected systems, can pay dividends if a decryptor is later released. Third, the scale of the damages in this case, estimated at 100 million Swiss francs for three ransomware families, provides a benchmark for the financial risk that ransomware poses to mid-sized and large enterprises. The cost of a single successful ransomware attack against a major company can exceed the total damages attributed to an entire family of malware, underscoring the need for robust prevention, detection, and backup strategies.

The broader lesson is that ransomware is not simply a technological problem but a criminal enterprise that spans multiple countries, legal systems, and layers of technical and organizational specialization. Disrupting that enterprise requires a coordinated response that includes technical countermeasures, legal prosecution, international cooperation, and internal organizational resilience. The Swiss verdict is a step in that direction, but it is one step in a much longer journey. Organizations should treat it as confirmation that the legal system can and will pursue ransomware actors, but should not rely on that alone to protect themselves. The most effective defense against ransomware remains a combination of rigorous security hygiene, comprehensive backup and recovery planning, employee training, and active threat intelligence sharing with the broader security community.

Questions answered
  • What was the sentence for the Ukrainian ransomware developer?The Zurich court sentenced him to 12 years and 9 months in prison, plus a 10-year ban from Switzerland.
  • Which ransomware families did the developer create?He was convicted for developing LockerGoga, MegaCortex, and Nefilim ransomware.
  • How much damage did the ransomware cause?The three ransomware families caused an estimated 100 million Swiss francs ($123 million) in damages.
Share This Article