Hacker Who Helped Stop Global Cyber-Attack Arrested in US

Advertisement
By Associated Press | Updated: 4 August 2017 09:30 IST
Highlights
  • Hutchins credited with derailing WannaCry cyber-attack in May
  • News of his detention came as a shock to the cyber-security community
  • He is charged with creating and distributing the Kronos malware

Marcus Hutchins, a young British researcher credited with derailing a global cyber-attack in May, was arrested for allegedly creating and distributing malicious software designed to collect bank-account passwords, US authorities said Thursday.

News of Hutchins' detention came as a shock to the cyber-security community. Many had rallied behind the researcher whose quick thinking helped control the spread of the WannaCry ransomware attack that crippled thousands of computers.

Advertisement

Hutchins was detained in Las Vegas on his way back to Britain from an annual gathering of hackers and information security gurus. A grand jury indictment charged Hutchins with creating and distributing malware known as the Kronos banking Trojan.

Such malware infects Web browsers, then captures usernames and passwords when an unsuspecting user visits a bank or other trusted location, enabling cyber-theft.

Advertisement

The indictment, filed in a Wisconsin federal court last month, alleges that Hutchins and another defendant - whose name was redacted - conspired between July 2014 and July 2015 to advertise the availability of the Kronos malware on internet forums, sell the malware and profit from it. The indictment also accuses Hutchins of creating the malware.

Authorities said the malware was first made available in early 2014, and "marketed and distributed through AlphaBay, a hidden service on the Tor network." The US Department of Justice announced in July that the AlphaBay "darknet" marketplace was shut down after an international law enforcement effort.

Advertisement

Hutchins' arraignment was postponed Thursday in US District Court in Las Vegas by a magistrate judge who gave him until Friday afternoon to determine if he wants to hire his own lawyer.

Hutchins was in Las Vegas for Def Con, an annual cyber-security conference that ended Sunday. On Wednesday, Hutchins made comments on Twitter that suggested he was at an airport getting ready to board a plane for a flight home. He never left Nevada.

Advertisement

Jake Williams, a respected cyber-security researcher, said he found it difficult to believe Hutchins is guilty. The two men have worked on various projects, including training material for higher education for which the Briton declined payment.

"He's a stand-up guy," Williams said in a text chat. "I can't reconcile the charges with what I know about him."

A Justice Department spokesman confirmed the 22-year-old Hutchins was arrested Wednesday in Las Vegas. Officer Rodrigo Pena, a police spokesman in Henderson, near Las Vegas, said Hutchins spent the night in federal custody in the city lockup.

Andrew Mabbitt, a British digital security specialist who had been staying in Las Vegas with Hutchins, said he and his friends grew worried when they got "radio silence" from Hutchins for hours. The worries deepened when Hutchins' mother called to tell him the young researcher hadn't made his flight home.

Mabbitt said he eventually found Hutchins' name on a detention center website. News of his indictment Thursday left colleagues scrambling to understand what happened.

"We don't know the evidence the FBI has against him, however we do have some circumstantial evidence that he was involved in that community at the time," said computer security expert Rob Graham.

The big question is the identity of the co-defendant in the case, whose name is redacted in the indictment. Why was it blacked out? "Maybe the other guy testified against him," said Graham.

The co-defendant allegedly advertised the malware online. Hutchins is accused of creating and transmitting the program.

Williams, the president of Rendition Infosec, speculated that the co-defendant might have been caught up in the takedown of AlphaBay and framed Hutchins in exchange for a plea deal.

The problem with software creation is that often a program includes code written by multiple programmers. Prosecutors might need to prove that Hutchins wrote code with specific targets.

Williams pointed to a July 13, 2014 tweet by Hutchins, whose moniker is @MalwareTechBlog, asking if anyone had a sample of Kronos to share.

"I've written code that other people have injected malware into," said Graham. "We know that large parts of Kronos were written by other people."

One legal scholar who specializes in studying computer crime said it's unusual, and problematic, for prosecutors to go after someone simply for writing or selling malware - as opposed to using it to further a crime.

"This is the first case I know of where the government is prosecuting someone for creating or selling malware but not actually using it," said Orin Kerr, a law professor at George Washington University. Kerr said it will be difficult to prove criminal intent.

"It's a constant issue in criminal law - the helping of people who are committing a crime," Kerr said. "When is that itself a crime?"

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Oppo Reno 16c Could Be the Most Affordable Reno 16 Series Model in India
  2. Xiaomi Wants a Bigger Space in Your Home: Large Appliance Push Confirmed
  3. Vivo Y6e 5G With 6,500mAh Battery Debuts at This Price
  4. JBL Live 780NC, Live 680NC Debut in India With Up to 80-Hour Battery Life
  5. Oppo Reno 15A 5G Arrives With a 7,000mAh Battery at This Price
  6. Oppo Reno 16 Series Will Launch in Indonesia, Malaysia on These Dates
  7. Honor 600 Smart 5G Listed on French Website, Could Launch Soon
  8. Narwal S20, S20 Pro and S30 Vacuum Cleaners Debut in India: See Price
  9. iQOO Z11i Design, Colourways Revealed Ahead of China Launch
  1. iQOO Z11i Design, Colour Options Revealed Ahead of Anticipated Launch in China
  2. Oppo Reno 16c to Reportedly Launch in India Alongside Reno 16; Specifications Tipped
  3. Chandra Captures Sharpest-Ever X-Ray View of M87 Black Hole Jet
  4. Honor 600 Smart 5G With 7,700mAh Battery Listed on French Website, Could Launch Soon: Price, Features
  5. Rockstar Games Confirms GTA 6 Pre-Orders Will Begin June 25, Reveals New Cover Art
  6. Oppo Enco Air 5 India Launch Teased; Amazon Availability Confirmed
  7. Huawei FreeBuds 7i, FreeBuds SE 4 ANC Launched in India With Up to 50 Hours of Total Battery Life: Price, Features
  8. Aztec Hit With Second Security Breach, Days After Hackers Used Exploit to Steal $2.19 Million
  9. FilterCopy’s For The Real Me Season 1 Now on Instagram: Know Everything About This Micro-Drama Reel Series
  10. Narwal S20, S20 Pro, S30 Wet and Dry Vacuum Cleaners With Up to 20,000Pa Suction Launched in India:Price, Features
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.