LockerGoga Developer Faces 12 Years in Swiss Ransomware Trial
A 52-year-old Ukrainian software developer is on trial at Zurich District Court over allegations that he helped an international ransomware group target companies with LockerGoga, MegaCortex and Nefilim. Swiss prosecutors are seeking a 12-year prison sentence, the defendant’s expulsion from Switzerland, and the recovery of 1.8 million Swiss francs ($2.2 million) in alleged criminal proceeds. The unidentified defendant denies developing malware or participating in ransomware attacks and has been detained since October 2021.
Prosecutors allege that the developer was a key contributor to a group that breached corporate networks, stole data, encrypted systems and extorted victims. Alleged targets included Swiss train manufacturer Stadler Rail, banking software provider Crealogix and building technology company Meier Tobler. Investigators say the group attacked 10 companies in Switzerland and other countries between December 2018 and May 2020, causing estimated losses exceeding 130 million Swiss francs ($160 million). The international investigation involved authorities in Switzerland, France, the Netherlands, Norway, Ukraine and the United States.
The defense said ransomware source code found on the defendant’s devices belonged to a cybersecurity client for whom he worked as a consultant. His lawyers also challenged the evidence chain, saying investigators failed to maintain complete seizure records. Prosecutors further claim that Ukrainian hacker Oleksandr Ieremenko, who operated from Moscow, directed attacks involving the defendant, citing testimony that Ieremenko had protection from Russia’s Federal Security Service. Ieremenko died after falling from a Moscow building in 2022, but the cause of his death remains undetermined; prosecutors presented no evidence that the defendant had direct ties to Russian intelligence. A verdict is expected in September. The defendant also faces separate child sexual abuse material charges after investigators reportedly found nearly 7,000 images and more than 500 videos in an encrypted file. Organizations reviewing their own exposure can use an open port scanner to identify exposed services and an SSL/TLS checker to validate public certificate and configuration weaknesses.