Ukrainian malware developer gets nearly 13 years in Switzerland over ransomware attacks
A Ukrainian IT specialist has been sentenced to 12 years and nine months in prison in Switzerland for his role in ransomware attacks that caused an estimated 100 million Swiss francs ($123 million) in damage.
The Zurich District Court found the 52-year-old man played a key role in attacks on companies including Swiss train manufacturer Stadler Rail, building technology company Meier Tobler and financial software provider Crealogix.
He was identified as the lead developer of Lockergoga, Megacortex and Nefilim malware, which was used to encrypt victims' data and demand ransom payments.
In the attack on Stadler Rail, the man stole about 500 gigabytes of confidential data and threatened to publish it. The company refused to pay the ransom, while some other victims did make payments.
The court said the Ukrainian was not the mastermind behind the operations but developed the malware and passed it to people who selected targets and coordinated the extortion attempts. Those organizers have not been identified.
The defendant denied knowingly participating in criminal activity, saying he had worked as an IT security consultant for an unidentified client. The court rejected his account, noting that extortion messages were also found among data seized from him.
Prosecutors said a suspected instigator behind the attacks had previously cooperated with Russian intelligence and died after falling from a window in Moscow in 2022. They also argued that the cyberattacks overlapped with Russian efforts to cause economic disruption in Western countries.
However, there is no evidence that the convicted man himself had direct links to Russian intelligence.
The court also banned him from Switzerland for ten years. The ruling is not final and can be appealed.
- Share:
