In May 2017, a 22-year-old on a week off sat in his childhood bedroom in Ilfracombe, Devon, and stopped the WannaCry ransomware attack, which had hit more than 230,000 computers in 150 countries and forced UK hospitals to turn away patients. Marcus Hutchins noticed the worm tried to contact a long, gibberish, unregistered domain. He registered it for about $10 to track infections, and the spread stopped. The domain was an anti-analysis check that he had turned into a global kill switch.
A few months later, FBI agents detained him at the Las Vegas airport after DEF CON. This episode explains why. As a teenager on HackForums he built a botnet of 8,000 computers, then wrote a rootkit called UPAS Kit for an anonymous contact named Vinny. After he gave Vinny his home address, Vinny used it to blackmail him into adding keylogging and web injects, and the result was sold as the banking malware Kronos. Hutchins later quit, started the MalwareTech blog, and was hired by Kryptos Logic.
- At 14 he built a password stealer that exploited Internet Explorer’s autofill, and his school banned him from its computers over a breach he denied.
- Vinny got his real address by offering to mail him drugs as a birthday present, then threatened to hand his identity to the FBI.
- A power outage cost him over $5,000 of a contact named Randy’s Bitcoin, and the chat logs from making it right later tied him to Kronos.
- In 2018 he refused a deal offering zero prison time in exchange for becoming an informant, and prosecutors added four more charges.
- In 2019 he pleaded guilty to two charges and was sentenced to time served and one year of supervised release, with the judge noting he had already turned the corner.
Leave a Reply