Opens in a new tab

Swiss developer goes on trial over global ransomware attacks

Wednesday 19th August 2026 on 09:01 in Switzerland

cybercrime, Ransomware, Switzerland

A Swiss-based software developer accused of helping hack and extort hundreds of companies worldwide is on trial at the Zurich District Court. SRF reported that the proceedings will also examine whether Swiss law enforcement is equipped to deal with modern digital crime.

The 52-year-old, who was born in Ukraine, was arrested five years ago at his apartment in the canton of Basel-Landschaft. He has lived in Switzerland with his family for more than 10 years and works as a software developer.

Prosecutors allege that he belonged to a group that began attacking companies around the world in 2019. The group allegedly broke into computer systems, encrypted data and demanded ransom payments. From 2020, it also used so-called double extortion, stealing data before encryption and threatening to publish it.

One of the group’s early victims was Altran, a French consulting company. In January 2019, the attackers allegedly locked system administrators out of the network, encrypted files and systems, and affected 250 servers and additional devices at different locations.

After three days of negotiations, Altran agreed to pay 410 Bitcoin, worth 1.4 million Swiss francs at the time. The attackers allegedly moved the Bitcoin through a mixer to obscure the trail and divided the proceeds. The Swiss-based developer is alleged to have received about 25,000 Swiss francs.

The total damage to Altran was substantially higher than the ransom, according to the indictment. It included business interruptions and the cost of cleaning the IT systems, with the total damage put at least in the tens of millions of francs.

The group later attacked Stadler Rail, a Swiss company. Investigators believe the attackers probably used employees’ login details to enter its systems. They allegedly explored the network, obtained extensive access rights, copied as many files as possible to their own systems and then encrypted Stadler’s data.

The attackers demanded 6 million US dollars from Stadler, half for decrypting the data and half for not publishing it. An undercover officer from the Thurgau cantonal police handled the communication during negotiations that lasted several days. Stadler eventually ended the talks.

From the end of May 2020, the attackers published the company’s internal files on their website over several weeks. According to the indictments, Stadler suffered around 5 million Swiss francs in damage from business interruptions and the work required to clean its systems, in addition to an unquantifiable loss of reputation.

Prosecutors allege that the defendant developed the malware used in the attacks, first Lockergoga, then Megacortex and finally Nefilim.

At the time of his arrest, he was allegedly developing more sophisticated software called RMS. The program was intended to automate the entire chain of a cyberattack through a simple user interface, from breaking into a system and spreading through it to causing damage.

The accused allegedly employed a team of six people to develop RMS. The indictment calls the software a “hell machine” that would have made cyberattacks easily accessible to a very large number of people.

Prosecutors also allege that the well-paid developer worked on the project during evenings, weekends and working hours. In court, he denies all the allegations and says he knew nothing about them.

Source 
(via SRF)