Swiss Court Sentences Ukrainian Ransomware Developer to 12 years 9 months for LockerGoga, MegaCortex, and Nefilim Campaigns
What Happened – A Zurich court sentenced a 52‑year‑old Ukrainian man to 12 years 9 months in prison and a ten‑year ban from Switzerland for creating the LockerGoga, MegaCortex and Nefilim ransomware families. The malware was used against global enterprises—including Norsk Hydro, Stadler Rail, Hexion and Momentive—causing roughly CHF 100 million in damages and, in some cases, the theft of confidential data.
Why It Matters for Trust & Control Assurance
- The case highlights the need for continuous monitoring of third‑party code and supply‑chain risk to detect malicious tooling before it is weaponised.
- Effective incident‑response and evidence‑preservation processes are essential to demonstrate a defensible audit trail after a ransomware event.
- Mapping ransomware‑related controls to a unified framework provides reusable proof for multiple compliance regimes.
Who Is Affected – Manufacturing (aluminium, chemicals, rail), industrial engineering, and any organisation that relies on on‑premise OT/IT networks.
Recommended Actions
- Review and map your ransomware‑response controls (backup integrity, network segmentation, incident‑response playbooks) to the Verisq Common Framework.
- Implement continuous evidence collection for backup testing, log retention, and third‑party code reviews.
- Conduct tabletop exercises that simulate a LockerGoga‑style encryption event and capture audit‑ready documentation.
Source: Bitdefender Blog – Ukrainian ransomware developer jailed for nearly 13 years
Technical Notes
- Ransomware families: LockerGoga, MegaCortex, Nefilim.
- Damage estimate: ~CHF 100 million (≈ US $123 million).
- Notable victim outcomes: network shutdown at Norsk Hydro; 500 GB data exfiltrated from Stadler Rail (no ransom paid).
- Bitdefender released a free LockerGoga decryptor in 2022, enabling victims to recover files without paying.
Source: same as above