Bluewin.Ch Zurich Prosecutor Seeks 12-Year Sentence for Ransomware Developer Linked to Russian Strategy
Article Content
- •The defendant is accused of developing the 'Lockergoga' ransomware, causing millions in damages.
- •Prosecution seeks a 12-year prison sentence and deportation for the accused hacker.
- •The case highlights potential connections between cybercriminals and state-sponsored actors.
A Ukrainian software developer accused of extorting companies through ransomware is facing trial in Zurich. The prosecution claims he was a key developer of the 'Lockergoga' ransomware, which targeted firms like Stadler Rail and Crealogix, causing millions in damages. The defendant, who has been in custody since October 2021, denies developing malware, stating the source code on his devices was from a client in IT security. The prosecutor argues that ransomware attacks are part of a broader Russian strategy to destabilize Western companies, although no direct links to Russian intelligence have been established. The trial has garnered significant media attention, with strict security measures in place at the courthouse.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track LockerGoga and Crealogix in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Ukrainian Hacker Sentenced for Ransomware Attacks on Swiss Companies A 52-year-old Ukrainian hacker was sentenced to 12 years and 9 months in prison by the Zurich District Court for his role in ransomware attacks targeting multiple firms, including Stadler Rail. The hacker developed malware used in extortion schemes, causing estimated damages of around 100 million Swiss francs ($123…
Citrix NetScaler Critical Vulnerabilities Exploited: Urgent Patching Required Citrix NetScaler ADC and Gateway products are affected by critical vulnerabilities CVE-2026-88771 and CVE-2026-88772, both assigned a CVSS score of 9.5. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on September 27, 2026, and mandated…