WannaCry hero Marcus Hutchins arrested by FBI over allegations he created Kronos banking...

midian182

Posts: 9,730   +121
Staff member

Three months ago, just as the WannaCry outbreak was at its height, 23-year-old British security researcher Marcus Hutchins made international headlines after accidentally discovering a hidden “kill switch” that stopped the ransomware from spreading. On Wednesday, as he was about to fly home from Las Vegas after attending the Def Con hacking conference, the FBI arrested the man who had been hailed a hero.

News of his arrest led to some conspiracy theorists claiming Hutchins was somehow linked to WannaCry, which many experts believe came from North Korean hackers The Lazarus Group, but a US Department of Justice indictment shows this isn’t the case. Hutchins, better known as MalwareTech, is accused of helping to create, spread, and maintain the banking Trojan Kronos between 2014 and 2015. "Defendant Marcus Hutchins created the Kronos malware,” it alleges.

Hutchins has been charged alongside another unnamed co-defendant, who’s accused of doing most of the work to spread the malware. The person is also said to have uploaded a YouTube video explaining how Kronos works, something the DoJ seems to consider evidence. The same day the video went up, Hutchins posted a tweet asking for a sample to analyze.

The co-defendant is also accused of selling Kronos on dark web marketplace Alphabay, which authorities closed down several weeks ago. It was sold on the malware forums for prices up to $7000, though the indictment lists prices of $2000 and $3000.

Only one part of the indictment suggests Hutchins worked on Kronos after it was actively being used for criminal purposes. He is accused of helping to update the malware in February 2015, six months after it went on sale.

Cybersecurity experts have expressed skepticism at the indictment. "It’s not a crime to create malware. It’s not a crime to sell malware. It’s a crime to sell malware with the intent to further someone else’s crime." George Washington University law professor Orin Kerr told Wired. "This story alone doesn’t really fit. There's got to be more to it, or it’s going to run into legal problems."

Hutchins became an unintentional saviour when he created a website found in WannaCry’s code that turned out to be a kill switch. The ransomware stopped infected new computers when it detected the URL had been registered.

Whether Hutchins was genuinely just researching Kronos, or if he’s another example of a former black hat hacker who moved on to legitimate security research, is unknown. But whatever the case, the arrest marks a drastic change in fortunes for the man who was so recently praised as a hero.

Permalink to story.

 
Well I guess he WannaCry now. He looks just like a regular stereotypical nerd one would imagine. All that's missing in the shot is the empty pizza boxes and fizzy cold drink cans.
 
Did he think doing one good deed would give him some kind of immunity? That is just plain dumb .....
 
Did he think doing one good deed would give him some kind of immunity? That is just plain dumb .....
We don't know all the details but chances are the US government screwed up somewhere or jumped to conclusions based on faulty reasoning. The FBI has raided homes with no linking evidence other than an IP address. In many cases the home owners had an open WiFi and the person they were after was smart enough not to use an Internet connection linked to them.
 
He's innocent until proven guilty. They need to believe they have beyond a reasonable doubt evidence in order to arrest him and charge him with a crime.

Most likely, they are just going to flip him to work for them. Or, alternatively, they will extradite him and the UK will use him. This is a very common trade in the world of cyber security. Many of the leading experts in the field used to be gey-market hackers.

His help with WannaCry is a good sign to authorities that he is willing to play ball. A federal indictment is nothing to brush off.
 
Does this mean that when the next WannaCry type malware starts circulating, nobody is going to try to combat it for fear that the FBI will dig up all their dirty secrets and make them disappear off the face of the planet?
 
Wow, I didn't know he was convicted yet.

Or are you making assumptions again?

Immunity is often granted in lue of prosecution in criminal courts in order to obtain testimony ...... sheeze, I wish you would invest a little of mental effort before blurting out the next thing you think of ... this is like the 3rd or 4th time!
 
This sounds like a good idea for a movie. The federal government creates this badass virus and sets it out on the world. Then when someone figures out how to stop it they approach him to see if he will work for them, he says no. The government responds by laying blame on him......
 
This sounds like a good idea for a movie. The federal government creates this badass virus and sets it out on the world. Then when someone figures out how to stop it they approach him to see if he will work for them, he says no. The government responds by laying blame on him......
Sounds about right, with details of the actual hack theft of 140 trillion not the poor take of 140k.
 
Immunity is often granted in lue of prosecution in criminal courts in order to obtain testimony ...... sheeze, I wish you would invest a little of mental effort before blurting out the next thing you think of ... this is like the 3rd or 4th time!
What are you even talking about?
 
He's innocent until proven guilty. They need to believe they have beyond a reasonable doubt evidence in order to arrest him and charge him with a crime.

Most likely, they are just going to flip him to work for them. Or, alternatively, they will extradite him and the UK will use him. This is a very common trade in the world of cyber security. Many of the leading experts in the field used to be gey-market hackers.

His help with WannaCry is a good sign to authorities that he is willing to play ball. A federal indictment is nothing to brush off.
This is US we are talking about, where prosecutors are running around destroying people life just to make a career in politics later on. Ever saw one of those dipshits and their trials? Nothing short of Stalin's '30s political trials except that they are doing it for themselves and their future careers ...
 
Back