Crealogix, Stadler Rail and Meier Tobler: Ukrainian software developer faces 12 years in Swiss ransomware trial

Crealogix, Stadler Rail and Meier Tobler: Ukrainian software developer faces 12 years in Swiss ransomware trial

Swiss Prosecutors Seek 12-Year Sentence for Ukrainian Developer in Major Ransomware Case

Swiss prosecutors are pursuing a 12-year prison sentence and expulsion from Switzerland for a 52-year-old Ukrainian software developer accused of playing a central role in a global ransomware operation. The defendant, whose name remains undisclosed, went on trial in Zurich District Court this week for alleged involvement in attacks using LockerGoga, MegaCortex, and Nefilim ransomware, which targeted high-profile victims, including Swiss train manufacturer Stadler Rail, banking software firm Crealogix, and building technology company Meier Tobler.

Prosecutors claim the defendant was a key developer for an unnamed cybercriminal group that breached corporate networks, stole data, and encrypted systems to extort victims resulting in over $160 million in damages across 10 attacks between December 2018 and May 2020. They also seek the forfeiture of 1.8 million Swiss francs ($2.2 million) in alleged criminal proceeds. The defendant, who has been in custody since October 2021, denies the charges, asserting that ransomware code found on his devices belonged to a cybersecurity client for whom he worked as a consultant. His defense has challenged the integrity of the digital evidence, citing incomplete investigative records.

The case is linked to Oleksandr Ieremenko, another Ukrainian hacker accused of orchestrating the attacks from Moscow. Swiss prosecutors allege Ieremenko had ties to Russia’s Federal Security Service (FSB), though no direct evidence connects the defendant to Russian intelligence. Ieremenko reportedly died in 2022 after falling from a window in Moscow, with authorities unable to determine whether his death was accidental, a suicide, or foul play.

The investigation began after ransomware attacks in Zurich in 2019 and later expanded into a multinational effort involving authorities from Switzerland, France, the Netherlands, Norway, Ukraine, and the U.S. In addition to cybercrime charges, the defendant faces allegations related to child sexual abuse material, with Swiss media reporting that investigators found thousands of exploitative images and videos in an encrypted file during a search. A verdict in the case is expected in September.

Source: https://therecord.media/ukrainian-software-developer-court-switzerland

Meier Tobler cybersecurity rating report: https://www.rankiteo.com/company/meier-tobler-ag

CREALOGIX cybersecurity rating report: https://www.rankiteo.com/company/crealogix

Stadler cybersecurity rating report: https://www.rankiteo.com/company/stadler-rail

"id": "MEICRESTA1787056557",
"linkid": "meier-tobler-ag, crealogix, stadler-rail",
"type": "Ransomware",
"date": "12/2018",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': 'Manufacturing (Train)',
                        'location': 'Switzerland',
                        'name': 'Stadler Rail',
                        'type': 'Corporation'},
                       {'industry': 'Banking Software',
                        'location': 'Switzerland',
                        'name': 'Crealogix',
                        'type': 'Corporation'},
                       {'industry': 'Building Technology',
                        'location': 'Switzerland',
                        'name': 'Meier Tobler',
                        'type': 'Corporation'}],
 'data_breach': {'data_encryption': True, 'data_exfiltration': True},
 'description': 'Swiss prosecutors are pursuing a 12-year prison sentence for '
                'a 52-year-old Ukrainian software developer accused of playing '
                'a central role in a global ransomware operation. The '
                'defendant is alleged to have been involved in attacks using '
                'LockerGoga, MegaCortex, and Nefilim ransomware, targeting '
                'high-profile victims and causing over $160 million in '
                'damages.',
 'impact': {'brand_reputation_impact': True,
            'data_compromised': True,
            'financial_loss': '$160 million',
            'operational_impact': True,
            'systems_affected': True},
 'investigation_status': 'Ongoing (Verdict expected in September)',
 'motivation': 'Financial gain',
 'ransomware': {'data_encryption': True,
                'data_exfiltration': True,
                'ransomware_strain': ['LockerGoga', 'MegaCortex', 'Nefilim']},
 'references': [{'source': 'Swiss Prosecutors Case'}],
 'regulatory_compliance': {'legal_actions': True},
 'response': {'law_enforcement_notified': True},
 'threat_actor': ['Unnamed cybercriminal group', 'Oleksandr Ieremenko'],
 'title': 'Major Ransomware Operation Involving LockerGoga, MegaCortex, and '
          'Nefilim',
 'type': 'Ransomware'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.