Decoding the world of cybersecurity

Swiss ransomware trial tests digital evidence

Swiss prosecutors are seeking a 12-year sentence in a ransomware case where the defendant disputes his alleged role and the handling of seized digital evidence.

Swiss ransomware trial tests digital evidence
Summary
  • A 52-year-old Ukrainian developer is on trial in Zurich over alleged involvement with LockerGoga and related ransomware operations.
  • Prosecutors are seeking 12 years in prison and an expulsion order of the same duration.
  • The defendant denies developing ransomware and is challenging the admissibility and documentation of digital evidence.

A Swiss ransomware prosecution has reached trial with the defence challenging both the defendant’s alleged role in the attacks and the integrity of digital evidence gathered during the investigation.

The 52-year-old Ukrainian software developer went on trial at Zurich District Court on Monday over alleged involvement in operations using LockerGoga and other ransomware. Swiss prosecutors are seeking a 12-year prison sentence and an expulsion order of the same duration.

The defendant, whose name has not been publicly disclosed by Swiss authorities, denies developing ransomware or taking part in the attacks.

Prosecutors allege that he was a leading developer in a cybercriminal operation responsible for attacks against companies in Switzerland and abroad. Swiss victims cited during the proceedings include Stadler Rail, building-technology company Meier Tobler, and banking-software provider Crealogix.

The prosecution is also seeking recovery of CHF1.8 million in alleged criminal proceeds. Wider reporting on the indictment attributes more than CHF130 million in estimated losses to attacks in which prosecutors say the defendant participated.

Attribution is being tested in court

The defence says ransomware source code found on the defendant’s devices came from work performed for a cybersecurity client. It has also questioned the admissibility of digital evidence, arguing that investigators did not maintain complete documentation of the raw data they seized.

That challenge moves the case beyond the technical identification of malware. A criminal prosecution has to establish who performed particular acts, how evidence links an individual to those acts, how seized material was preserved, and whether alternative explanations for code or infrastructure found on a device can be excluded to the standard required by the court.

Those questions are difficult in ransomware cases because the underlying operations are distributed. Developers, intrusion specialists, affiliates, infrastructure providers, negotiators, and money-laundering networks can sit in different countries and interact largely through digital systems.

The Swiss investigation grew out of attacks against Zurich companies in 2019 and later became part of international law-enforcement work involving several countries. Similar investigations into the LockerGoga, MegaCortex, and Nefilim ecosystems have continued long after individual ransomware brands stopped dominating the threat landscape.

Forensic evidence gathered during those operations can include malware samples, seized devices, server records, financial information, online identities, communications, and material supplied by foreign investigators. Converting that body of intelligence into admissible evidence against one defendant is a different task from attributing a campaign in an incident-response report.

The defendant has been in custody since October 2021. The allegations remain contested, and a verdict is expected in September.

The proceedings will therefore test not only whether Swiss prosecutors can connect a developer to a major ransomware operation, but whether years of cross-border digital investigation can withstand scrutiny over evidence provenance and attribution in an ordinary criminal court.

×