TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Researcher Who Stopped WannaCry Ransomware Detained in US After Def Con

567 pointsby Shinkiroualmost 8 years ago

27 comments

dangalmost 8 years ago
Since <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=14922563" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=14922563</a> adds significant new information (or at least I assume it does), the discussion can shift there now.
评论 #14927441 未加载
maxericksonalmost 8 years ago
CNN got the indictment:<p><i>On Wednesday, 22-year-old Marcus Hutchins -- also known as MalwareTech -- was arrested in Las Vegas for &quot;his role in creating and distributing the Kronos banking Trojan,&quot; according to a spokesperson from the U.S. Department of Justice.<p>The charges relate to alleged conduct occurring between July 2014 and July 2015.<p>According to an indictment provided to CNN Tech, Hutchins created the malware and shared it online. </i><p><a href="http:&#x2F;&#x2F;money.cnn.com&#x2F;2017&#x2F;08&#x2F;03&#x2F;technology&#x2F;culture&#x2F;malwaretech-arrested-las-vegas-trojan&#x2F;index.html" rel="nofollow">http:&#x2F;&#x2F;money.cnn.com&#x2F;2017&#x2F;08&#x2F;03&#x2F;technology&#x2F;culture&#x2F;malwarete...</a>
jstanleyalmost 8 years ago
&gt; &quot;I&#x27;ve spoken to the US Marshals again and they say they have no record of Marcus being in the system. At this point we&#x27;ve been trying to get in contact with Marcus for 18 hours and nobody knows where he&#x27;s been taken,&quot; the person added. &quot;We still don&#x27;t know why Marcus has been arrested and now we have no idea where in the US he&#x27;s been taken to and we&#x27;re extremely concerned for his welfare.&quot;<p>What the hell? How does something like this even happen? Surely they can&#x27;t just take somebody away and keep it a secret?
评论 #14921965 未加载
评论 #14922015 未加载
评论 #14923607 未加载
评论 #14921289 未加载
评论 #14921979 未加载
评论 #14922053 未加载
评论 #14921368 未加载
downandoutalmost 8 years ago
FYI, if you&#x27;ve committed any form of cybercrime in the previous 3 years (edit: the statute of limitations is 5 years for most federal computer crimes, as pointed out below), you should avoid such conferences in the US for exactly this reason. You probably aren&#x27;t as smart as you think, and there may be a sealed arrest warrant for you.<p>The FBI waits for these kinds of conferences to do exactly what they did here. Another Las Vegas DEF CON victim was Dmitry Sklyarov [1]. They won&#x27;t bother with all of the problems associated with international arrest warrants and extradition if they know you&#x27;re coming to them.<p>[1] <a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;United_States_v._Elcom_Ltd" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;United_States_v._Elcom_Ltd</a>.
评论 #14922776 未加载
评论 #14923050 未加载
评论 #14923068 未加载
评论 #14923266 未加载
评论 #14923126 未加载
mnm1almost 8 years ago
No good deed goes unpunished. But why is DefCon still in the US? I think the creators of the conference might want to seriously think about holding it somewhere that isn&#x27;t so hostile to pretty much everyone who attends.
评论 #14922341 未加载
评论 #14921673 未加载
评论 #14923520 未加载
评论 #14924278 未加载
samwillisalmost 8 years ago
The Guardian has more:<p><a href="https:&#x2F;&#x2F;www.theguardian.com&#x2F;technology&#x2F;2017&#x2F;aug&#x2F;03&#x2F;researcher-who-stopped-wannacry-ransomware-detained-in-us" rel="nofollow">https:&#x2F;&#x2F;www.theguardian.com&#x2F;technology&#x2F;2017&#x2F;aug&#x2F;03&#x2F;researche...</a><p>He may have a shady past:<p><pre><code> According to an indictment released by the US Department of Justice, Hutchins is accused of having helped to spread and maintain the banking trojan Kronos between 2014 and 2015&quot;</code></pre>
评论 #14922497 未加载
评论 #14922604 未加载
QUFBalmost 8 years ago
This sends a clear message to the global whitehat security community: travel to the US at your own peril.
评论 #14921707 未加载
评论 #14921397 未加载
评论 #14922334 未加载
评论 #14922477 未加载
mholtalmost 8 years ago
Bitcoin wallets associated with WannaCry have been emptied: <a href="https:&#x2F;&#x2F;arstechnica.com&#x2F;gadgets&#x2F;2017&#x2F;08&#x2F;wannacry-operator-empties-bitcoin-wallets-connected-to-ransomware&#x2F;" rel="nofollow">https:&#x2F;&#x2F;arstechnica.com&#x2F;gadgets&#x2F;2017&#x2F;08&#x2F;wannacry-operator-em...</a>
评论 #14923227 未加载
holtalanmalmost 8 years ago
I&#x27;m curious what charges are being brought against him. For all we know, this detention is completely unrelated to WannaCry. We shall see.
评论 #14921438 未加载
评论 #14921749 未加载
评论 #14922026 未加载
sajal83almost 8 years ago
UK&#x27;s National Cyber Security Centre on MalwareTech&#x27;s arrest: &quot;We are aware of the situation. This is a law enforcement matter and it would be inappropriate to comment further.&quot;<p><a href="https:&#x2F;&#x2F;twitter.com&#x2F;josephfcox&#x2F;status&#x2F;893160214664445952" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;josephfcox&#x2F;status&#x2F;893160214664445952</a>
评论 #14921925 未加载
评论 #14922259 未加载
cromwellianalmost 8 years ago
Reading the indictment, it seems like his partner ratted him out. Curious though, the indictment seems to list the redacted partner as doing most of the incriminating things (posting a video demonstration, advertising the sale on AlphaBay, etc), it merely accused Marcus as being the author and co-conspirator.<p>I wonder if his partner&#x2F;friend got caught, and plea bargained to turn state&#x27;s evidence against Marcus.
评论 #14923249 未加载
评论 #14923190 未加载
评论 #14924175 未加载
openmosixalmost 8 years ago
Indictment: <a href="https:&#x2F;&#x2F;www.documentcloud.org&#x2F;documents&#x2F;3912524-Kronos-Indictment-R.html" rel="nofollow">https:&#x2F;&#x2F;www.documentcloud.org&#x2F;documents&#x2F;3912524-Kronos-Indic...</a>
评论 #14922830 未加载
djvdorpalmost 8 years ago
Maybe this is the reason he did not appreciate people revealing his identity online (basically DOXing him for fun, some journalist did it if I recall correctly). It really sucks when somebody that is trying to do well (stopping the WannaCry Ransomware as he did) is detained, even though we don&#x27;t know more details at this points, this hits him rather personally and probably not for the good, I am very sorry for him and I hope he gets out soon and that all is well.
jessaustinalmost 8 years ago
They&#x27;re surprisingly clever, to arrest after DefCon. Typical stupid USA LEOs would arrest ASAP, so the unjust detention could be a cause célèbre hyped up by half the talks.
评论 #14921869 未加载
评论 #14924393 未加载
评论 #14922789 未加载
danesparzaalmost 8 years ago
This reminds me of Kevin Mitnick: <a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Kevin_Mitnick#Arrest.2C_conviction.2C_and_incarceration" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Kevin_Mitnick#Arrest.2C_convic...</a><p>Do we need to create some &quot;Free Marcus&quot; bumper stickers?
评论 #14921777 未加载
评论 #14922411 未加载
rocky1138almost 8 years ago
Why in heaven&#x27;s name did he travel to the US?
评论 #14921840 未加载
评论 #14921818 未加载
评论 #14922048 未加载
评论 #14921991 未加载
评论 #14921983 未加载
评论 #14921812 未加载
评论 #14921908 未加载
c-slicealmost 8 years ago
The bitcoin ransom wallets for WannaCry were just emptied today as well. What was the time difference between these two events? It seems possible that Hutchins could have had control of the wallets and fed seized the coins.
cjsukalmost 8 years ago
I&#x27;d like to know on what grounds?
评论 #14922034 未加载
评论 #14921989 未加载
评论 #14922021 未加载
abhi3almost 8 years ago
Why are people in this thread so outraged without knowing any of the facts? For all we know there might be a legitimate charge on which he was arrested.<p>As per him being untraceable, if he was not read his rights then the FBI just jeopardized their own case. If no one knows where he is, it&#x27;s more likely that it&#x27;s what Marcus wants at the moment rather than what the FBI wants.
评论 #14921521 未加载
评论 #14922005 未加载
评论 #14921600 未加载
评论 #14922785 未加载
评论 #14923330 未加载
mzsalmost 8 years ago
better summary: <a href="http:&#x2F;&#x2F;www.reuters.com&#x2F;article&#x2F;us-usa-cyber-arrest-idUSKBN1AJ2IC" rel="nofollow">http:&#x2F;&#x2F;www.reuters.com&#x2F;article&#x2F;us-usa-cyber-arrest-idUSKBN1A...</a><p>insightful thread also delving into wannacry: <a href="https:&#x2F;&#x2F;twitter.com&#x2F;3L3V3NTH&#x2F;status&#x2F;893181445824446464" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;3L3V3NTH&#x2F;status&#x2F;893181445824446464</a><p>edit: there is a nice HN discussion already about the bitcoin: <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=14918545" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=14918545</a>
moominalmost 8 years ago
Maybe he violated WannaCry&#x27;s terms of service. The DoJ are pretty down on that kind of thing.
评论 #14922117 未加载
cnkkalmost 8 years ago
yeaaah let us arrest the good guys...
评论 #14923940 未加载
评论 #14921585 未加载
elormalmost 8 years ago
As much as this article contains very little information,this sounds very much like something the US will do.<p>Whenever someone has to be the butt of some global joke .....somehow the US has to be the one to step up. Taking someone into custody for 18 hours without giving the family or press any information. How different is this from Iran or North Korea?<p>Two things could&#x27;ve happened here IMO. They asked for the domain to turned over to them and were politely refused, or they&#x27;re about to punish an accidental hero for white hat work&#x2F;previous black hat work not related to WannaCry
评论 #14923107 未加载
评论 #14923502 未加载
评论 #14923363 未加载
评论 #14921501 未加载
评论 #14921651 未加载
featherversealmost 8 years ago
This is some seriously shady shit. The smart bet is we&#x27;re not getting the whole story.<p>&quot;Buy guns, lock your doors.&quot; - Bill Hicks
BigChiefSmokemalmost 8 years ago
Trump&#x27;s Dept of Justice is out of control.
AndrewKemendoalmost 8 years ago
--
评论 #14921543 未加载
评论 #14921399 未加载
评论 #14921713 未加载
评论 #14921532 未加载
Traytorzalmost 8 years ago
I like how this malware writer&#x2F;researcher claims he &quot;found&quot; the address and &quot;miraculously saved&quot; everyone by grabbing the domain.<p>Not sure why everyone says he isn&#x27;t the malware writer. What proof do you have that he didn&#x27;t write it? Maybe he left a trail that you missed.
评论 #14922174 未加载
评论 #14922094 未加载
评论 #14926197 未加载