- A court in Zurich handed a 52-year-old Ukrainian man a sentence of 12 years and nine months for his part in several ransomware attacks.
- He helped develop the LockerGoga, MegaCortex, and Nefilim malware strains, though he wasn’t the leader of the larger criminal operation.
- The case also links to fugitive suspect Volodymyr Tymoshchuk and the late hacker Oleksandr Ieremenko.
A 52-year old Ukrainian ransomware developer, Artem Melnik, will serve 12 years and nine months behind bars for his role in ransomware attacks, according to SWI’s report. According to Swiss prosecutors, Melnik had contributed to building ransomware used on companies not only in Switzerland but also in other countries.
Court documents named three different malware strains: LockerGoga, Nefilim, and MegaCortex. The attacks targeted big organizations and caused significant losses. The court found that Melnik worked as a developer. It did not find him to be the person who led the full crime group.
Court Rejects Melnik’s Defense
Melnik denied the charges during the trial. He told the court that he worked as an IT security expert. Melnik said a client had given him the ransomware code found on his systems. He claimed he did not know that criminals would use the code. The court did not accept that account.
Investigators also found ransom and extortion messages in his stored data, according to reports from the trial. Those messages added to the case against him. The court found that Melnik built the malware and passed it to other operators. Those operators then picked targets and ran the ransom attacks.
Swiss Firms Faced Attacks
The case named several Swiss companies as victims. They include rail maker Stadler Rail, building technology firm Meier Tobler and software company Crealogix.
Prosecutors estimated that losses amounted to around CHF 100 million, but some Swiss media reports a larger sum of over CHF 130 million. The totals differ because investigators can count business losses, recovery costs and other damage in different ways.
U.S. records connect the ransomware strains LockerGoga, MegaCortex, and Nefilim to attacks not only in the United States, but across Europe and other regions, too.
Ukraine has also faced major cyber threats linked to destructive malware campaigns in the past. The country remains at risk of further attacks following the damage caused by NotPetya, one of the most disruptive cyberattacks associated with Ukraine.
Prosecutors say attackers hit over 250 American companies between July 2019 and June 2020. On top of that, they went after hundreds more businesses around the world.
The Case Implicates Another Hacker Named Leremenko
The Swiss trial also shed light on Ukrainian hacker Oleksandr Vitalyevich Ieremenko. Swiss prosecutors said Ieremenko directed attacks linked to Melnik. They said he operated from Moscow.
Prosecutors also cited testimony that claimed Russian security officials protected him. The testimony included claims about links to Russia’s Federal Security Service, or FSB.
Those claims remain allegations from the Swiss case. They do not prove that Russia’s security service directed the ransomware attacks.
Ieremenko already had a record in U.S. cybercrime cases. U.S. officials say he helped run a major hacking and securities fraud operation that used stolen SEC data. Ieremenko died in Moscow in 2022 he fell out of a window. Nobody seems sure if it was an accident, suicide, or something more sinister, at least that’s what Swiss prosecutors say.
Another Suspect Remains Free
The wider case also includes Volodymyr Viktorovych Tymoshchuk. U.S. authorities say Tymoshchuk used the names Farnetwork, Deadforz, Boba and MSFV. Tymoshchuk is accused of working as the administrator of three ransomware strains LockerGoga, MegaCortex, and Nefilim.
Last September, the US Department of Justice unsealed new charges against him. They said he contributed to attacks against over 250 US companies and hundreds more worldwide.
Tymoshchuk operated Nefilim as a ransomware-as-a-service, according to prosecutors. Other hackers carry out the attacks while he takes a cut of whatever ransom payment they receive. Tymoshchuk remains outside U.S. custody.
The latest FBI wanted notice shows a reward of $10 million or more for information that helps in arresting him. The general reward in the U.S. in September 2025 provided a reward of up to $11 million for Tymoshchuk and other related suspects.
A Network with Separate Roles
Swiss prosecutors said the attacks caused heavy damage to victims. The case also shows why ransomware groups often use partners in several countries. That setup can make each attack harder to trace and prosecute.
One person could write the malware. Another could find a company with weak security. Others could break into the network, steal files or demand money.
That model also appears in the U.S. case against Tymoshchuk. Later, the Nefilim group used a service model. Administrators gave other criminals access to the ransomware and took part of the ransom money.
The U.S. case has also reached another suspect, Artem Stryzhak, a Ukrainian national. U.S. officials extradited Artem Stryzhak from Spain in 2025. He admitted his involvement with the Nefilim operation.
US and European agencies later released decryption keys for both LockerGoga and MegaCortex to help victims recover files without paying ransom. Melnik’s conviction just adds another chapter to this long, complicated international case.
He now faces a long prison term in Switzerland. Tymoshchuk remains wanted by U.S. authorities. Ieremenko is dead, and prosecutors said they could not establish how he died.
The case shows the different roles that can exist inside a ransomware operation. Developers, administrators, and attackers can work in different places while serving the same criminal scheme.
Share this article
About the Author
Rebecca James is an IT consultant with forward thinking approach toward developing IT infrastructures of SMEs. She writes to engage with individuals and raise awareness of digital security, privacy, and better IT infrastructure.
More from Rebecca JamesRelated Posts
German Chancellor Merz Renews Call for Real-Name Internet Rules Amid Privacy Debate
German Chancellor Friedrich Merz reaffirmed his position on the adoption of real name policy on the ...
WhatsApp Tests ‘Restricted Chat’ Privacy Feature to Keep Chats Off Linked Devices
WhatsApp is testing a privacy tool called Restricted Chat that keeps a conversation on your main pho...
Palo Alto Networks Warns of Critical PAN-OS Flaw Allowing Remote Code Execution
Palo Alto Networks found a serious bug in its PAN-OS firewall software. Hackers do not need a passwo...
New Mantax Otax Android Malware Combines Ransomware, Spyware and Harassment
Mantax Otax is an Android malware strain operated by Indonesian threat actors that fuses file encryp...
Hacker Claims 600,000 Tax Records Stolen From Colombia’s Cali Government
A threat actor claims to have accessed a database from the Office of the Mayor of Santiago de Cali c...
Microsoft Fixes Record 974 Security Flaws as Two Windows Bugs Face Active Attacks
Microsoft fixed 974 security flaws this Patch Tuesday, its biggest release ever. Two Windows bugs ar...