Ukrainian ransomware developer jailed for nearly 13 years
At a glance
- Severity
- Low
- Used in attacks
- No flaws named
- Reported by
- 1 outlet
A court in Zurich has sentenced a Ukrainian man to 12 years and nine months in prison, and banned him from Switzerland for ten years, for developing ransomware that blackmailed companies around the world.
The 52-year-old man, who according to local media reports had been living in the Basel-Landschaft region but has not been named, found by the court to be the lead developer of the LockerGoga, MegaCortex, and Nefilim families of ransomware.
Past victims of the ransomware include Norwegian aluminium giant Norsk Hydro which had its networks crippled globally, train manufacturer Stadler Rail (which had 500 GB of confidential data stolen in 2020, and refused to pay a reported US $6 million ransom), and chemical companies, Hexion and Momentive.
In all, prosecutors claimed that some 100 million Swiss Francs (US $123 million) worth of damage was caused by the ransomware attacks.
The man denied knowing that the software he created was being used for crime, and claimed that the reason why he had the ransomware's source code at his home was that he had been working as a cybersecurity consultant for an unnnamed client.
To be fair, the court appears to have viewed the unnamed man as the builder of the malware, rather than the person who chose which companies to target or one of those who ran the actual blackmail campaigns. All the same, in the eyes of the law that did not make him an innocent party.
Last year, prosecutors in the United States unsealed charges against suspected cybercrime kingpin Volodymyr Tymoshchuk, alleged to be an administrator of the LockerGoga, MegaCortex, and Nefilim ransomware - believed to have been used against hundreds of companies worldwide.
The US State Department is offering rewards of up to US $11 million for information leading to the arrest or conviction of Tymoshchuk and his cohorts.
Ukrainian national Tymoshchuk allegedly released new strains of his ransomware whenever old ones had been decrypted. In 2022, experts at Bitdefender released a free decryptor for LockerGoga in co-operation with law enforcement.
As a result, if there is anyone out there who suffered a historic LockerGoga attack and has not yet been able to decrypt their files, there is still a chance that they could now potentially recover them without paying a penny to cybercriminals.
Originally published by Graham Cluley. © Graham Cluley. Written by Graham Cluley.
Fastnexa security experts
Dealing with this in your own company?
If this story touches software, suppliers or systems you use, a Fastnexa security expert can tell you what it means for you and what to do first.
Think you’ve already been hit? Don’t wait on a form: call or WhatsApp +1 (732) 454 2616. We reply within 1 hour, 24/7. Emergency help →
Coverage
One outlet has carried this so far.
2026-09-24 12:42 UTC
Related stories
- Teenager suspected of leading KillSec ransomware group
Hacker News · 2026-10-04
- Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware
The Hacker News · 2026-10-03
- N0n ransomware: what you need to know
Graham Cluley · 2026-10-03
- Warlock ransomware breach SharePoint in water, telecom operator attacks
BleepingComputer · 2026-10-02
- Defending against AI-fueled cyberattacks requires focus on identity, data governance, Microsoft says
Cybersecurity Dive · 2026-10-02