In short
Darknet Diaries - Episode 158: MalwareTech
Episode Overview In this episode, host Jack Rhysider interviews Marcus Hutchins, widely known as MalwareTech, recounting his unexpected rise to fame after he inadvertently halted the WannaCry ransomware attack, one of the largest cyber assaults in history. The story intricately weaves through Hutchins' background as an anonymous security researcher, the timeline of events during the WannaCry incident, and the legal troubles that followed.
Key Themes and Discussions
Introduction of MalwareTech
- Background: Marcus Hutchins is an anonymous security researcher focused on malware analysis and threat intelligence.
- Privacy: Utilized a cat avatar on Twitter to maintain anonymity; no photos available online.
The WannaCry Ransomware Attack
- Timeline: The ransomware began infecting systems in May 2017, affecting numerous organizations, especially UK hospitals.
- Mechanism: WannaCry exploited a vulnerability known as EternalBlue, developed by the NSA and leaked by a group called the Shadow Brokers.
- Nature of Infection: Unlike traditional ransomware, WannaCry was described as "wormable," allowing it to spread autonomously between computers.
The Kill Switch
- Discovery: Hutchins found an unregistered domain in WannaCry's code, which he registered as a kill switch.
- Impact: This action unexpectedly halted the rampant spread of the ransomware, leading to his recognition as a hero.
Media Attention and Anonymity Lost
- Publicity: Following the halt of WannaCry, Hutchins faced intense media scrutiny, losing his anonymity. Major publications like the Daily Telegraph published his name and personal details.
- Personal Struggles: The newfound fame led to overwhelming situations, including constant attention from journalists and the public.
Legal Troubles
- FBI Arrest: While returning to the UK, he was detained by the FBI, facing allegations related to his prior development of banking malware (Kronos).
- Charges: Faced multiple charges including conspiracy to commit wiretapping, with the legal framework being complex and obscure.
The Fight for Justice
- Mental Toll: The prolonged legal battle was stressful and taxing, leading Hutchins to question the justice system's approach.
- Decision to Plead Guilty: After a lengthy battle and numerous denied motions, he ultimately decided to plead guilty to the charges to end the stress.
Sentencing
- Outcome: The judge sentenced him to time served, considering his role in stopping WannaCry and the lack of proven damages caused by Kronos.
- Reflection: Hutchins reflects on the duality of WannaCry being both a catastrophic event and a catalyst for personal growth.
Community Support
- Fellow Hackers: Many in the cybersecurity community rallied to support him during his legal troubles, showcasing the camaraderie among hackers.
Conclusion
- Personal Growth: Hutchins acknowledges the stress he endured but also recognizes the positive transformation that arose from the experience.
Episode Takeaways
- Anonymity vs. Fame: The balance between being a private individual and the public's curiosity can lead to unexpected challenges.
- Cybersecurity Landscape: The evolving nature of cyber threats and the importance of understanding malware behavior.
- Legal System Challenge: The intricacies of the legal system, especially concerning cybersecurity offenses, and the moral dilemmas faced by individuals within it.
- Community in Cybersecurity: The importance of support networks in the hacker community during crises.
Final Thoughts This episode provides a profound look into the life of Marcus Hutchins, illustrating the complexities of being a cybersecurity expert in a world filled with threats and the unintended consequences of heroism in the digital age.
Written by AI. May contain mistakes. Listen to the episode to check what was said.
Transcript
Automatic transcript. May contain errors.0:00Oh my gosh, oh my gosh, oh my gosh, I'm squealing over here. After years and years of trying to get today's guest on the show, he finally said, yes, I'm so excited for this one. I've been sliding into his DMs for years. Hey, can I interview you? And I swear he always has the same answer every time. He's like, who are you? And I say something like, oh, I'm a podcaster and I really want to hear your story. And he's like, no, thank you. And fair answer. I wouldn't want to talk to me either if I was in his position. and then I saw him at a party at DEF CON and when I first approached him in person he was hiding behind a sign trying not to be seen so I stand out in a crowd so I've learned that signs are my best friend we can hide behind the lamppost we can hide behind the tree we can hide behind the sign but if I stand in the middle of the room it's going to draw a lot more attention than I necessarily maybe want although I've got to the point now where I think I can just handle it But I do remember our first interactions.
1:03I think part of the awkwardness was, I'm very bad at recognizing faces, and you were wearing a mask the first time you saw me. It's true. I had a disguise on, and yeah, I asked to interview him, and he had no idea who I was. He's just like, who are you? In my defense, there is no photos of you online, and I have checked. So there is no way I could have known. It's true. I tried real hard not to have any photos of me on the internet. I'm a very private person. But I swear, every time I asked him for an interview, he just kept asking me the same thing. Who are you? No, thank you. So I remember we had quite a long conversation.
1:42And then you went away and you came back without the mask. And then you came back and you sort of went to re-engage the conversation. And I had no idea who you were. I was like, who is this random guy? Okay, fair point. I wear a lot of disguises. So you're right. Some of this is on me. But I'm happy to announce that today, finally, I am interviewing Malware Tech. I'm Malware Tech, and I'm an anonymous security researcher.
2:13These are true stories from the dark side of the internet.
2:20I'm Jack Recider. This is Darknet Diaries.
2:41This episode is sponsored by NetCraft. Every Darknet Diary story starts with a scam, a breach, or a crime. NetCraft works behind the scenes to not only disrupt the threat, but to remove the infrastructure that enables adversaries to launch more attacks. Uncovering phishing kits, dismantling malware networks, and disrupting brand abuse at scale, Netcraft stops threats across the open web, social platforms, and the dark web. Trusted by leading internet and infrastructure providers and brands large and small, they clean up the web a little more every day. Proudly earning one-star reviews from cybercriminals and five-star reviews from customers, Netcraft's automated brand protection platform sifts through the noise to deliver high-fidelity signal that powers takedowns at any scale.
3:24Keep your story off this podcast by learning more at netcraft.com slash dnd. That's netcraft.com slash dnd.
3:42This episode is sponsored by SpyCloud. With ransomware affecting 85 % of organizations in the past year and phishing becoming the top entry point to ransomware, taking action on your company's exposure has never been more critical. I recently visited spycloud.com to check my darknet exposure and was shocked to discover just how much stolen identity data criminals have at their disposal. Spycloud's new identity threat report reveals that nearly half of all corporate users have been infected by info stealer malware at some point. With 63.8 billion distinct identity records now circulating on the dark web, the scale of this threat is staggering.
4:19What's even more alarming is that only 38 % of organizations can actually detect these historical identity exposures that create ongoing risk. Knowing what's putting you and your organization at risk, from stolen credentials to session cookies to PII, is critical for protecting against identity-based threats like account takeover, session hijacking, and yes, even ransomware. With SpyCloud, you're never in the dark about your company's exposure from third-party breaches, successful fishes, or infostealer infections. Read the full report and check your Darknet exposure for free at spycloud.com slash darknetdiaries.
4:54That's spycloud.com slash darknetdiaries. We're going to start this story in early 2017. As he said, his name is Malware Tech and he's an anonymous security researcher. He would research malware and then publish his findings anonymously under the name Malware Tech. He never posts his picture on the internet. His Twitter profile is just a picture of a cat wearing glasses. Nobody knew who he was or what he looked like. So I've been a cybersecurity analyst since about 2016. I mostly specialized in a combination of malware, reverse engineering, and cyber threat intelligence. So my job was basically to reverse engineer botnet malware and then find ways to monitor their C2 infrastructure in a way that we could actually see who was being infected.
5:49So our goal was to sort of do external threat intelligence. So rather than being on someone's network and saying, hey, look, there's a sign that you're infected with malware, our goal was to be on the bad guy's network and be able to see all the victims of the malware and then alert them to the fact that they're infected. Where were you living? Was it Cornwall at the time? So I was Devon, so just north of Cornwall, pretty close to the border, actually. What is that? I think I watched a show, like there's TV shows based out of Cornwall and I think it was Dr. Martin, was it? Yeah, that was the one, yeah.
6:20I think that there were some episodes in Devon, but I remember my parents were very excited. They called me one time and they were like, there's some famous people filming in our town and like we live in the middle of nowhere. So there's no famous people there. Any kind of filming is like a huge deal. So you've probably seen it on the TV like once or twice. Yeah, I have. It's a very picturesque place. It's beautiful. Yeah, so where I live, which is in North Devon, we have this massive long, I think it's like three, four mile long beach, beautiful golden sand. It picks up a nice Atlantic swell that I think comes from the hurricanes down in the Gulf.
7:00They'll occasionally swing north towards the southwest coast of England. So we actually get some really, really big surf down there. So living so near the sea, I was like, well, what do I do for hobbies? Because we had moved from inland, so I'm like, I need new hobbies. What do people here do? And the obvious answer was surfing. So I took up surfing. Turned out it's a really, really fun sport. But a lot of people don't associate it with England. They think England is like rock beaches, pebbles. Usually they're thinking of places like Blackpool. But there are some really, really good surf spots on the southwest coast, and I just happened to live right next to one.
7:40Basically, I wake up one day and it's all over the news that this ransomware is infecting lots and lots of British hospitals. And we start with breaking news this hour. A number of procedures have been cancelled or redirected to other NHS providers following a cyber attack on some of London's major hospitals. The ransomware would soon be called WannaCry. And it was hitting tons of hospitals around the UK. Their computers would get infected and then completely encrypted. You couldn't use it at all. And you had to pay Bitcoin to get it unlocked again. This infection forced hospitals to turn away patients and cancel procedures.
8:20It was awful. So I think the consensus is that it was someone working on behalf of the North Korean government. It's very interesting how this came about, too. We believe it was the NSA that developed the exploit, which they called Eternal Blue. Which, by the way, the NSA found this exploit in Windows. Microsoft Windows, an American company, but didn't tell Microsoft that they have this really bad vulnerability in Windows. And it absolutely flabbergasts me that NSA discovers vulnerabilities in US companies and then not tell those companies that their product is vulnerable to attack. But it gets worse.
8:58Then the NSA somehow lost control of this exploit, and it ended up in the hands of someone calling themselves the Shadow Brokers. And just the set of circumstances that led to WannaCry was so insane. Because, of course, you have the Shadow Brokers leak, and the Shadow Brokers, they haven't been attributed yet, but it's widely believed to be Russian intelligence. So Russian intelligence hacks the NSA, steals one of their most prized vulnerabilities, leaks it onto the open internet, at which point North Korea pick it up and decide to make ransomware with it. And we're not even to this day sure whether WannaCry was supposed to be released yet.
9:39There are a lot of just signs in the code that it might have been a work in progress that accidentally leaked a little earlier than they had intended it to. We think the North Koreans unleashed ransomware on the world just to try to make some money, which is wild. Other nation states are not doing cyber thug activity like this, trying to make some money through ransomware. But North Korea does it. But one reason we think the exploit got released too soon was because it was discovered pretty early on that there's no way to track who paid the ransom. Usually ransomware would generate a unique Bitcoin address for every single victim.
10:16And then they can tell if that victim paid by telling if there is a payment in that Bitcoin wallet. But there was a bug with the code where it only generated something like three Bitcoin wallets. So all of the payments are going to these three Bitcoin wallets. They have no way to trace who paid and who didn't. So while I think it was intended to be ransomware or intended to at a later date be ransomware, at the time that it was released or got out, it was essentially a file shredder. There wasn't really any realistic way to get your data a bag. What scumbags? You know, like, for one, for a country to extort hospitals to try to make a little bit of money, I mean, come on.
10:56But two, to release ransomware so bad that it doesn't even work right. It just cripples businesses with no way to undo it. So North Korea didn't make much money from this and simply gave the world a black eye for no reason. I think a lot of what went into
11:17early that the files weren't decryptable. Like almost immediately when the first infections happened, analysts, they raised the alarm, they went to the press and they were like, don't pay the ransom. Like you're not going to get your data back. Of course, all this news is right up Malware Tech's alley. Malware research is his bread and butter. He wants to know more. Now, the thing with ransomware is back then, it was mostly spread by phishing email. So if you see a organization or two infected, that's pretty normal but if you're seeing like 10 20 30 different uh parts of the same organization being infected that's either a lot of people falling for phishing attempts or it's not phishing and my first instinct was this isn't phishing this is hitting way too many organizations way too many parts of the same organization it has to be something bigger so i i went and asked my friend caffeine can i have a sample of this and the second i looked at it i was like oh this is this is bad like this isn't your standard ransomware because at that time ransomware was purely spread by phishing or botnets i don't think anyone had ever made wormable ransomware before and i was like this ransomware spreads from computer to computer completely unaided it doesn't need a user to click a malicious link or open a weird email.
12:40It will literally just get onto a computer, look for other computers to hack and then hack them and infect them and just repeat that process over and over. And that was the point where I was realizing we are dealing with something that I don't think has ever been seen before. This thing was spreading fast. Hundreds of networks were spreading it to hundreds more. Soon thousands were infected, all trying to spread it to thousands more. The internet was burning like an out-of-control wildfire that day. I was tasked with stopping the ransomware. And historically, when I worked with ransomware, it's almost impossible to stop.
13:23Sometimes you can decrypt it retroactively. There's flaws in the encryption. You can break the encryption and get people's files back. But in terms of stopping actively spreading ransomware, that is almost impossible. Sometimes there'll be a vulnerability where we can hack into their command and control server and put a stop to it. So that's what we were looking for. But as he looked through the ransomware code, he noticed something. There's a strange domain name in this code, a URL. Just a long string of gibberish letters with.com at the end. He looked. The domain wasn't registered. And when I saw this unregistered domain in the WannaCry code, I was like, nice, this is probably a command and control server.
14:11So I registered it. And then I started looking, what can I do with this code? Like, what can I do with the control of this domain? I'm thinking it's a command and control server, and maybe we can exploit a vulnerability in the WannaCry code, maybe crash the malware, or anything that could stop it from spreading. But it actually turned out, while we were trying to figure out what is the purpose of this domain, what does it actually do, we had already stopped WannaCry because the domain was a kill switch. Without him even realizing it, the moment he made this domain active, the WannaCry malware stopped.
14:50Just suddenly and surprisingly stopped spreading. Someone had basically just posted on Twitter that WannaCry has been stopped. Like someone has activated a kill switch in WannaCry, and we actually didn't know we had activated the kill switch until several hours later. The purpose of this domain in the code was before the malware spreads, it first checks to see if the domain is up and alive. And if it is, the malware stops everything it's doing. And since MalwareTech just registered it and set it up, That triggered the kill switch to essentially deactivate one of the most brutal, devastating ransomware attacks the UK has ever seen.
15:29By the time we actually got around to looking at the code, it was like it had already reached the media that we had stopped it. And we were like, oh, OK. Yeah, the media was reporting that someone stopped WannaCry before he even knew he did it. But wait, if he's got control of this domain, can he set some sort of monitoring tool up so that he can see what traffic is going to this domain? Yeah, so we're actually very lucky. We did this professionally. A lot of our work was about finding ways into botnets and then collecting these analytics. So we actually already had the system set up to do that, which was great.
16:08So I was like, awesome. We have all this analytics. We can see how many systems. WannaCry was hitting. But while I was focusing on that, everyone's like, who is this guy who's stopped the world's biggest ransomware attack? Meanwhile, I had no idea that that was going on until I checked Twitter and I was like, oh, oh. The thing is, is he was tweeting from his username, MalwareTech, all the analytics that were coming into this domain. And this made people realize Because malware tech is the guy controlling the kill switch. He's the one that stopped it, since he had all these analytics and could see what was going into that domain.
16:47But the thing is, not everyone put those pieces together like that. Some people thought, well, if he controls that domain, then that must mean he's the one who wrote the malware. So as far as a lot of law enforcement and intelligence agencies are concerned at the time being, I am the one who created WannaCry. I'm the person responsible for WannaCry, that is my domain and I'm controlling it. So it led to a very very interesting scenario because everyone was kind of confused about how did this happen? Why is the domain there and why does this random British teenager, well I think I was 22 actually so not quite a teenager.
17:28But they're like why does this random British dude control the domain that is in this massive piece of ransomware that is destroying networks all across the world? Did you discover all this in your parents' bedroom, by the way? I mean, in your parents' house? Yeah, so the unfortunate stereotype of the nerd in his parents' basement is true. It was technically not a basement because our house had multi-levels. The front door was a level higher than the back door. So it was technically a basement, but technically also not a basement. But I was basically in my parents' basement. Once the news got out that this guy MalwareTack is the one who stopped the world's biggest ransomware attack in history, his whole life changed.
18:17It went wrong in every way possible for me. I had set it up so the domain was registered through a proxy that shouldn't have traced back to me. But I think my Twitter gave them enough to find me. And my goal personally was to be an anonymous researcher. I had basically seen my whole career just being an anonymous researcher who no one needs to know my name. They don't need to know what I look like. I can just publish my blogs in peace and no one needs to like even know who I am. And then I got an email from, I believe, the Daily Telegraph. And they were like, we found your real name. We found your address.
18:54We found your parents' name. And we're going to publish it tomorrow. And we'd like comment. And I begged them, like, do not publish my name. don't publish my photo please just like respect my privacy but of course they had the the biggest story related to wanna cry so far uh the daily telegraph was the first person to actually correctly identify me so they knew they had a story that would get a lot of eyes and i i i kind of knew where this was going i was like i'm gonna beg them anyway but i know they're gonna publish this and i know it's all downhill from here i believe this was the monday so wanna cry happened on the friday i woke up monday they had published my name uh they had published my photo uh the daily mail had published my house address for some reason i remember reaching out to journalists and being like dude like what the hell is this like why would you possibly need to publish my home address in the UK's biggest newspaper after I've stopped a major criminal attack.
19:59Like this, this doesn't make any sense. And he like apologized and he took it out. But I was like, dude, like, like what, what, what goes through someone's mind to think everyone needs to know where this person lives. But yeah, so that day I woke up and my name was out there. Everyone knew it was me. I couldn't walk down the street without being recognized by someone in town. I was like, this is it. This is the end of an era. I'm no longer Malware Tech, the anonymous researcher. I'm now Marcus Hutchins. I remember just thinking, man, this is going to be such a, like, earth-shattering change to just the way I saw my life going.
20:50Once his name was out there, another paper, the Daily Mail, found a picture of him and published it. The headline read, Surf Dude Saves the Day. I think that was the two-page spread with my face on it, right? Yeah, front cover. Yeah. Yeah, so before that, no one knew what I looked like because I ran an anonymous Twitter account with a cat avatar, and I believe they were the first ones to actually get a real photo of me. And my mom, she reads the Daily Mail, so she came home and she handed me the newspaper, and there's my face across a two-page spread, and I'm like, oh my God.
21:30Marcus Hutchence was now world famous, and everyone wanted to talk with him even me there was this dude this one dude he kept ringing the doorbell like every single hour and then when we finally were like look you've got to stop doing this he just started calling instead like somehow he had our phone number and there was at one point there was several uh several journalists just like hanging around on the sidewalk outside my front door waiting for me to come out of the house uh of this funny story of me having to climb over the back fence to go and get food because these journalists just would not leave the outside of my house.
22:09And at the time, I just, I didn't understand why this was such a big deal. And as a very non-public person, it was, it was actually quite scary. Marcus is a private person. He's a bit awkward around people, very soft-spoken. He does not want this kind of spotlight on him. This was agonizing for him. He's tall and has huge poofy hair. You can spot him easily in a crowd. And people were stopping him to talk with him everywhere he went. Are you the guy who stopped the ransomware? And it wasn't just random people and journalists. Foreign intelligence was curious about him too. In the months after WannaCry, while the investigation was still ongoing before we knew that it was North Korea, there were a lot of foreign intelligence agencies.
22:55They weren't really sure what my role was. and there was actually one incident I remember quite clearly when I was traveling in a foreign country and some researchers from a neighboring country had invited us out to lunch. They were like, hey, we're really interested to hear about your research. Would you like to come to lunch with us? And they gave us an address and the address was across the border in their country. And I didn't see it as immediately suspicious because we were very close to the border of this country. so I'm like okay they're researchers from this country they're probably going to know more good restaurants in this country let's go meet them in their country for lunch and I got a tap on the shoulder by someone who I have no idea who they are who they worked for and they were like just so you know those are intelligence operatives of that country those people inviting you to lunch work for their foreign intelligence service I would maybe go get McDonald's or just go anywhere else.
23:56So you don't know who tapped you on the shoulder. It was just a stranger from the crowd and then they disappeared after that. Yep. It was one of the weirdest experiences I had in my life. That must have been for just to have some random person tell you that and then suddenly you, you know, the camera's zooming way out like, whoa, hold on. I assume it was probably someone from my country. I don't know. Why is someone from your country following you to another country while you're on vacation. That is crazy. I think it was someone following those people around and then they're like, wait, who's this guy they're talking?
24:31Oh, I see. It's entirely possible. We ended up on a lot of people's radars after WannaCry. My colleagues, not so much because they weren't as in the public eye as me, whereas I was the one who got tracked down first, so I took most of the heat. But I ended up having to actually go into a few different countries and speak to their law enforcement and tell them my side of the story because there was obviously a lot of suspicion. They're like, no one knew where WannaCry came from and I was the only tie to it. All they knew is that this worm just came from nowhere and there's only a single domain in the code and it's linked to Marcus Hutchins in Great Britain.
25:11So I basically ended up going on this sort of, almost like an apology tour, but without an apology because I'm not responsible. so I had to sort of give them my side of the story explain why we registered the domain how it came to that and eventually obviously I think it was it might have been October like it was a good like six or seven months after WannaCry that the the NSA and GCHQ and I think the Australian intelligence services they all came out and they pointed the finger at North Korea so after that the heat kind of died down but in that bit between stopping WannaCry and it being publicly attributed to North Korea I spent a lot of my time dodging very I don't know how to describe it but very suspicious situations I suspected that people had inferior intentions with either wanting to interview me or inviting me to their country to come and speak at their conferences.
26:10There was a lot of that in that period. So it was a very, very strange time in my life. Man, how crazy is that? To be invited to speak at another country and then to wonder, is this a ploy for some foreign intelligence operatives to arrest me? Or even worse, is North Korea mad at me and they want to pay me back for screwing up their ransomware and they're inviting me to this thing just so they can kidnap me? Marcus had to be very careful From now on, this sudden fame was attracting a lot of strange people. WannaCry hit in May of 2017. Three months after that was DEFCON, the annual hacker conference in Las Vegas in the U.S.
26:54Marcus had been there once before in 2016, and he liked it. So he flew out again in 2017. But little did he know that this DEFCON was going to radically change his life. So it was insane. I cannot even accurately describe the feeling of it. Try though. Try. Let's hear it. Yeah, so there's what we did personally and then there's what we did within the conference. So personally, what my friends had found out is that hotels in Vegas are ridiculously expensive and they basically calculated what could we afford if we just put all our individual hotel room uh costs together and got an airbnb instead and we found we could get one of the biggest mansions in las vegas with the largest private pool in i believe the entire state um so we went and we got this insane mansion and then we're like well the mansion's not complete without supercars right and there's a there's a car dealer in vegas that they let you rent supercars for like a day, two days, three days a week.
Read the full transcript
28:07So my friends, they went out and they rented supercars. So we had this driveway full of supercars. And they're not particularly expensive to rent for like short periods of time. But of course, I didn't realize that in the background, I was setting up this scene of me being this very, very wealthy person. when in reality the costs were split between about I think 8 to 12 people. So we had this crazy Vegas trip. We stayed in this massive mansion. We were driving around in supercars. We were shooting automatic weapons. You know, we just went all out on Vegas. Now the conference itself was very, very different.
28:48Now I had suspected I would get a fair amount of attention at the conference given how recent WannaCry was. It was only, I think, three months ago. But I had no idea the level that I was going to experience. I remember this was back when it was in Caesar's Palace, the actual casino before the forum. And anyone who's been will remember there's these hallways that are maybe like 20, 40 feet wide, and it's just shoulder-to-shoulder people all the way down the hallway. and I could not walk through the hallway because the traffic was moving so slowly that I would take a step someone would recognize me they'd come over and talk to me and by the time I got to take my next step someone else had come over and I had to get to this one event and it took me uh two hours and 15 minutes to walk a maybe like a hundred feet down the hallway and I was just like i need to go to my hotel room and hide like there's like an average 15 minute conversation will drain my social battery to the point where i need to sleep and i'm now at a level where i physically feel like i'm gonna pass out it was like one of the most crazy experiences i've ever had i just remember feeling like so overwhelmed because i i knew there was gonna be people who want to come up and talk to me i just didn't think it would be that many what was some of the stuff they were saying you oh it was it was all overwhelmingly positive like super heartwarming stuff like everyone was just really really positive they were all very kind very polite i don't think i had in the entire defcon a single negative interaction like people make out uh the hacking community to be all these like bad people and evil um but generally speaking i cannot think of a single negative interaction i had like everyone was so polite and so wonderful but then on the other side of this i'm just an introvert so i'm not used to this level of attention so inside i'm like this is really really like heartwarming and supportive but also i'm like i I feel like my entire body is on fire.
31:10Yeah. Wow, so what a weekend. You're going to fly back to the UK after that, right? Yeah, so I believe 2nd of August. We spent 10 days there. So 2nd of August, I was due to fly back to the UK. And so you have to go through the McLaren airport in Vegas. You get through security just fine? no so security was a little weird because usually when you go through security they they make you take any big items out your bag laptops ipads phones um and that is my experience with that airport like they always make you take your laptop out of your bag whereas with me they didn't they it seemed like they were speaking to me specifically and not the guests in general they like as I went to put my bags like to unpack my bag they said I'll just just leave everything in there and put it through and it felt like very weird at the time I was like it didn't look like they said that to anyone else other than me it looks like they specifically singled me out and I had a feeling I knew what was coming um I had a feeling that it was actually going to be related to WannaCry that the FBI had some questions for me and they were gonna pull me aside.
32:33But I was actually, I wasn't sure. So my bag goes through security just fine in the weirdest way possible. I go to the lounge and I think maybe an hour before my flight, a bunch of people in CBP uniforms approach me and I'm like huh because CBP is is customs and I'm trying to think what would I have done that would like would get me on the wrong side of customs and the only thing I could think of is this was the year that they had legalized recreational cannabis in in Las Vegas so I was like did I forget to take some some drugs out of my bag so I'm thinking they're pulling me aside because i forgot to take some weed out my bag they found it whatever and they take me to this back room and uh they take off the jackets and they they unroll these badges and it's fbi and i'm like oh okay so uh i did not know that was even something you were allowed to do to pretend to just be a different agency or if the people who took me would generally would genuinely also cvp but I get this back room in the airport and they identify themselves as FBI.
33:47And at this point, I still am not exactly sure why I'm being detained. I'm sorry, but I have to take a quick ad break here, but stay with us because Marcus is about to be very surprised about why the FBI is talking with him.
34:04This episode is sponsored by my friends at Black Hills Information Security. Black Hills has earned the trust of the cybersecurity industry since John Strand founded it in 2008. Through their anti-siphon training program, they teach you how to think like an attacker. From SOC analyst skills to how to defend your network with traps and deception, it's hands-on, practical training built for defenders who want to level up. Black Hills loves to share their knowledge through webcasts, blogs, zines, comics, and training courses all designed by hackers. For hackers! But do you need someone to do a penetration test to see where your defenses stand?
34:37Or are you looking for 24-7 monitoring from their active SOC team? Or maybe you're ready for continuous pen testing, where testing never stops and your systems stay battle-ready all the time. Well, they can help you with all of that. They've even made a card game. It's called Backdoors and Breaches. The idea is simple. It teaches people cybersecurity while they play. Companies use it to stress test their defenses. Teachers use it in the classroom to train the next generation. And if you're curious, there's a free version online that you can try right now. And this fall, they're launching a brand new competitive edition of Backdoors and Breaches, where you and your friends can go head to head hacking and defending just like the real thing.
35:14Check it all out at BlackHillsInfosec.com slash darknet. That's BlackHillsInfosec.com slash darknet. You have such a happy demeanor to you. So I imagine even in those first 15 minutes or so of like, oh, OK, we're actually the FBI. I still imagine you smiling and being like, oh, yeah, you know what? There were a thousand people who wanted to ask me about it. You want to cry? I'm sure you're just another one. What do you want to know? Did you have that kind of attitude? What was that first 15 minutes like? So I believe I was a bit hungover, but you are right. I always just have this happy demeanor.
35:52So I'm like, even when things are generally really, really bad, I always just am chill and happy to be there. So, yeah, I think I was a bit hungover, but otherwise I was like, okay, it's the FBI, whatever, I'll talk to them. But I hadn't quite yet figured out why they wanted to talk to me. Okay. And what were the questions they were asking you? So they started off with a bunch of random questions. It felt like they were deliberately trying to confuse me. They themselves were trying to obscure the reason why they had pulled me aside. so it felt like they were basically just fishing for information in a way that was designed to prevent me from realizing that i'm in trouble and i need a lawyer so they kind of presented themselves as these very uh just we're asking questions we're just some friendly fbi agents asking questions um and i thought it was about wanna cry until a good 30 minutes i think into the interview.
36:57So you know in the movies when they slide the document across the table and they ask you, do you know what this is? And usually it's like a photo of a murder or whatever. Yeah. So they did that. I didn't think that was a real thing they did, but they did that. Except in my case, they had basically printed off compiled code. So it was basically just 15 pages of just straight gibberish. So I'm going through these pages and they're like, do you know what this is? And I'm like, honestly, no, this is literal gibberish. But then one of the things with compiled code is any text that is present in the code is present in the however you were to print it off.
37:42So I get to the text section of the code and I start recognizing the strings and I'm like, oh, they printed off the Kronos executable. Like they've taken the compiled Kronos malware, opened it in Notepad or something, hit print, and this is what I'm looking at. And that was kind of the point where I realized, oh, I'm in like some serious trouble. But then I'm also trying not to laugh because someone has just tried to print an executable and hand it to me. Yeah, so I'm like toggling between almost smiling and oh shit, I'm like, I've really messed up. It is absolutely ridiculous. and they printed off a program and handed it to him.
38:22It wasn't readable code. It was compiled. Only a computer could read it. There's no way that anyone can read this gibberish, except there was one word in there which made Marcus realize what he was looking at, the Kronos malware. Kronos was a devastating banking malware. It was designed to get access into a victim's bank account, and then the person operating the malware can siphon funds out of the victim's bank. The FBI agents handed it to Marcus and asked him if he recognized it, and he did recognize it. Because before the world knew who Marcus Hutchins was, he was only known as Malware Tech, an anonymous security researcher.
39:05But before that, he was a malware developer. I started out as a malware writer. I specialized in writing rootkits. So that's malware that hides malware. So I mostly did stuff like Trojans that would do Bitcoin mining, stuff that's not super harmful, but also not really very great either. It's like the, not the worst of the worst, but obviously not something that I didn't deserve to go to jail for. Basically, he would write malware, which in itself is not so bad. It all depends on what you do with the malware, right? but he was working with someone who wanted to take his malware and sell it so they could make money.
39:48And so now his malware was being offered to criminals for sale. But still, by itself, his malware wasn't making any sales. Basically, we had a seller. So his job was to sell the malware. I would write the malware for him and then he would sell it. And then he announced to me that he had contracted this other programmer to combine my code with the banking code to make banking malware that he wanted to sell. So essentially, I had a choice. I was like, okay, so my code has just been made into banking malware. I am already implicated in this. What do I do? So I was like, I don't really want to, I don't want to have anything to do with this.
40:31Like I specifically said that any kind of credit card fraud or any kind of theft of money was over my moral line. I don't want anything to do with this. And that was the point when he basically hinted that if I didn't continue to maintain the code, he would drop my name and address to the FBI. So at that point, I was like, I'm in too deep. There is nothing I can do at this point. So as a teenager, he developed part of this Kronos malware. And now it was being bought by criminals and actively used to rob people's bank accounts. And he's actively supporting the code, adding in features, fixing issues.
41:15This made him worry. The second he told me that he had combined it with the banking malware, I was like, yeah, this is going to come back and bite me. There is no way that I am, like, I knew this was going to come. Like, I am going to be picked up by the FBI at some point. Like, this is going to come back to bite me. and like even then as a i think i was maybe 19 when this happened i knew the repercussions i was like this is this is bad he kept looking for a way out of this deal to stop working on the chronos banking malware but he feared that the guys he was working with were going to turn him in if he quit so i kept maintaining the code for about i want to say like six months a year until i found a way to to get out in a way that wouldn't result in him sort of doing anything to me.
42:07Like he wouldn't report me to the FBI or do anything that would harm me other than the harm that has already been done. So eventually about a year later, I find an out and I completely distance myself from a project. I think I spend about a year just doing blogging and then I get a job in cybersecurity. So I basically, I leave the life behind. I go into a professional cybersecurity role, and that's when I started doing this sort of malware-averse engineering and cyber threat intelligence. And so, in August 2017, on his way back from the most epic DEF CON ever, about to step foot on the plane, the FBI grabbed him and handed him a copy of his malware.
42:53And he knew exactly what that was. And he feared this day would someday come. At this point, he's missed his flight. His friends are worried about what happened to him, and he's starting to sober up. The smile faded. So, yeah, they took me to Overnight Holding, which is basically, it's like actual jail. So it's the jail you go to when you get arrested by the police for, like, being drunk and disorderly or whatever. Man, to be in jail with all the drunk and disorderly people from Las Vegas? That's got to be a real nightmare. Yeah, from the nice fancy mansion and the driving around in Lamborghinis to the concrete cell in, like, county jail.
43:38I don't know if it's even called county jail, but yeah, that was a very, very high high to a very low low. Now, the FBI needed to process him in order to charge him for these federal crimes, but it was getting late and the FBI agents were tired. So they just needed to dump Marcus somewhere for the night, and then the FBI would pick it up again in the morning and finish processing him. So they take him to the jail. And the jail was full. There were no free cells. So the police handcuffed me to a chair for the entire night. They were like, you're just going to be handcuffed to this chair in the lobby for the next 12 hours.
44:16And I was like, great, that's very comfortable. As a 6 '4 guy, I can think of no more comfortable way to sleep than in a lobby chair. um so i was a little upset at that point i was like okay i can understand the rest of the stuff but like you're gonna handcuff me to this tiny chair for 12 hours um but then i found a solution um i i need to go to the bathroom so i asked to go to the bathroom and it turns out the bathroom is just a cell that they leave vacant for people to use because each cell has its own toilet in it. So they have a spare one, which is like the visitor toilet. So I asked us to go to the bathroom and they throw me in that cell, they lock the door.
45:00And I'm like, well, how do I get back out? And I realized that you don't. You basically just stay locked in the bathroom until the next person uses the bathroom. So my plan for the night ended up becoming, I asked to go to the bathroom the bathroom is just a normal cell so it has a concrete bench i sleep on the nice comfy concrete bench then when someone else next needs to use the bathroom they take me out they handcuff me back to my chair i asked to use the bathroom again and that was basically my night is i just slept on a concrete bench in the designated public toilet cell oh yeah so um in overnight holding because a lot of the drunk people might like pass out and you know like end up in a in a state where they need medical attention the guards are supposed to do around every 20 minutes and check on all the cells um so there's a very loud audible alarm that goes off um to signal the guards to start their check and it goes off every 20 minutes basically you're just sleeping for 20 minutes at a time because you cannot sleep through that loud of an alarm.
46:06And I would put that as the rock bottom of my life. Like basically just sleeping on a concrete bench in a public toilet. So I think I get woken up at 4am in the holding facility. They wanted to like process me, which I'm like, why are you processing me? Like you're not keeping me. The FBI just left me here for you to deal with overnight, but I'm not staying. And I remember I was in a really bad mood because I had been woken up every 20 minutes for the entire night. My back hurt, my side hurt, every surface of my body hurt from trying to sleep on concrete. And then this guy's asking me all these questions, like, what's your sexuality?
46:47And I'm like, dude, I'm not doing this. So I told him, I'm not doing your intake form. Like, I'm not going to be in prison here. there is no reason for me to be up at four in the morning doing prison intake and i remember him saying to me you're not leaving here without it and i wanted to be snarky and i wanted to be like how much money do you want to bet on that and of course like a couple hours later the fbi just came and they're like we don't care whatever he did here he's ours they take me off to the the local i think it's like a a field office or maybe like some kind of satellite office They spend like an hour processing me, like fingerprints, hair samples, saliva sample, like you name it, photos.
47:33And then you get handed over to the U.S. Marshals. He gets taken to a federal detention center, basically a prison. He was locked up for the banking malware that he wrote when he was 19. And so there was nothing he could do but just sit there and see what fate has in store for him next. Someone who I actually didn't know at the time, her name's Tara Wheeler and Deviant Olam, who they're pretty well known in the hacking community. But I didn't know them and I had never met them. But they ran down to the courthouse and they posted my bail. Like they put up their own money. And this was cash bail.
48:13If you're not familiar with the bail system, typically if they set your bail at 30k, you can go and borrow the money from a bail bondsman. And it's usually, I think it's like a 10 % deposit. So you would just pay$3 ,000 and they'd put up the$30 ,000 for you. But when you have a cash bail, you have to pay the entire amount yourself. So they put up$30 ,000 of their own money to bail me out of jail. And that truly just blew my mind that a stranger, like someone I've never met, would be kind enough to do something like that for me. Tara and Deviant simply saw Marcus as someone who helped the world by disabling WannaCry.
48:53So they asked the hacker community to all pitch in and help bail out Marcus. And people did. Honestly, this is going to sound crazy, but it's true. I randomly ran into Tara myself at that time. We were on a remote island, deep in the woods of all places. And in the first few minutes of meeting her, she asked me, hey, we're raising money to help Marcus. Are you in? And I actually gave her some of my money myself. She made a good case on why it was important to help people in situations like this. and they raised enough money to spring them out of jail. I came into the U.S. on what's called an ESTA, which is a lot of countries have visa-free travel programs that allow you to visit as a tourist for 30 to 90 days without needing a visa.
49:37But you're not allowed to work on those, and you're not allowed to stay longer than the 30 to 90-day period. So I'm in the U.S. on a temporary visa, but my bail condition is I'm not allowed to leave the country until the case is over. and federal court cases go on for a long time like it's very very rare for a federal court case to go on for less than a year so i'm now in this sticky position where i need money to survive but i'm also legally not allowed to be in the country but i'm also legally not allowed to leave the country so i'm like huh um uh like do you guys have a protocol for this and they're like no like usually we don't arrest foreign nationals like this, or if you, when we do, you would be in jail.
50:22We've actually not had anyone be granted bail in this way. So I'm like, okay, so I guess I'm just on my own here. Like, I'm just going to have to figure it out myself. He was stuck, can't leave, can't work. Lucky for him, a few good lawyers heard about his case and wanted to help him. Yeah, so one of my lawyers lived in L.A., and my case was out in Milwaukee and as much as I love the people of Milwaukee, Milwaukee is not my scene. Like I'm a west coast kind of surfer vibe so I want to be near the coast, I want to be surfing, I want the nice warm weather and basically one of my lawyers made the argument that well like one of my lawyers is from LA and the other is from San Francisco so if I'm stranded in milwaukee anytime we need to do legal meetings they're both going to have to fly to me or i'm going to have to fly to one of them and the other is going to have to fly to one of them and it's like a logistical nightmare so my lawyers were like well wouldn't it make sense if he lived near one of his lawyers and the judge was like yeah that's actually uh the more sane way to do this so uh they basically agreed that i could go and live with uh like in the same city as one of my lawyers and I don't remember how or who chose it but it ended up being LA so I get moved to LA and I'd never been to LA before I didn't know what it was like I didn't know what to expect and I remember just kind of falling in love with the city within like two weeks which was pretty funny because a lot of the governments their strategy was give us what we want and we'll let you go home but after two weeks in LA I'm like actually you know I'm kind of good like I like it here they're like give us what you want and you can go home and i'm like no and they're like okay give us what we want and or we will deport you and i'm like but you can't deport me until the case is over um and it just it made things a little bit tricky for them because they had angled their whole case on this idea that i desperately wanted to go home to the uk which was no longer the case i actually i made a lot of new friends in la um i found like a lot of cool stuff to do.
52:36And I was like, you know what? I'm actually pretty happy here. So he became a bit of a beach bum. I mean, he couldn't work or leave. So surfing just became the thing he'd do right there on Venice Beach. Okay. So what charges do they have on you at this point? What are you facing? I actually don't know. This is going to sound absolutely insane, but I regularly have to Google what I was convicted of because it was very obscure. Because in the US, it is not illegal to write malware um you might intuitively think malware bad it's surely it's illegal it's not there is actually no federal law against writing malware so what they tend to do is they tend to find other laws that can be interpreted in such a way as to charge you with malware um now initially i think they hit me with six charges and then they later up to to 10 but they were all very obscure they were things like a conspiracy to commit wiretapping conspiracy to sell a wiretapping device a conspiracy to advertise a wiretapping device and their basic argument was that malware listens to keystrokes like it's like a keylogger and a keylogger is like a listing in on telephone calls um therefore we can use the wiretapping act to charge him with with what I would not call wiretapping, but they had argued is.
53:59So I'm being charged with a statute that was originally made for stopping people from listening in on telephone calls. I'm also being charged with conspiracy to commit computer hacking. And the way that works is if I am in any way involved with someone else doing hacking, they can charge me with conspiracy, being a part of a conspiracy. So they basically argued because someone used my malware to hack people and I wrote the malware and then it was sold to that someone, I am therefore a conspirator in whatever hacking happened. So although I had never used my malware to hack anyone and I had never hacked any systems, they got me on conspiracy to commit computer hacking.
54:43And I remember my lawyers explaining all this to me for the first time, and I was just insanely confused. Because in England, it's just illegal to write malware. So if I was charged in England, they'd be like, this is the no-writing malware law. You're being convicted of the no-writing malware. But in the US, it was just so obscenely complicated that I couldn't even wrap my head around what I was actually being charged with. I'm like, telephone wiretapping? This makes no sense. And here's the thing. Marcus knew that by creating the Kronos malware, what he did was wrong. He knew he should face charges for that.
55:19But these charges? No, these were not the right charges. And I've heard this time and time again from hackers on this show. They knew they did something bad. They were ready to face the consequences for it. But the charges that they were facing were for something else entirely. And that doesn't feel right. Like, if you steal$1 ,000 from someone and get caught, you know you're guilty, right? So when the police say, did you do it? Yep. Okay, great. Here are your charges. We know you worked with five other guys, and together you all stole$200 ,000, so you're facing 10 crimes total. Whoa, whoa, whoa, hold on.
55:55I only stole$1 ,000. This is not right. You know you're guilty of stealing, but not guilty of all the other stuff. And so you feel like you have to say, not guilty to all of the charges, since none of them match the actual crime you did. It's a broken system. At that point, I think I had decided to fight the case because what had basically happened is they had made it very clear to me that they did not care that I committed crimes. Like, this was not, you've done something wrong and we're bringing you to justice. They were very, very clear that they were only charging me to leverage me into becoming an informant and giving them up someone that they wanted.
56:38And at that point, I was kind of annoyed because in my mind, that's not how the justice system works, right? Like, you do a bad thing, you go to jail because you did a bad thing. Whereas they were saying, we don't actually care what you did. We just want this other guy. And I'm like, what? what um because this isn't uh i guess for the american listeners out there uh this is not how the uk system works in the uk you don't have plea deals and it's very very hard for prosecutors to do cases in this way the uk system is a lot more clear-cut you do a bad thing you get charged with the bad thing and you go to jail for doing the bad thing whereas the us is a lot more geared towards there's always a bigger fish they just they they want the bigger fish they don't really care about you or what you did.
57:24And this was, of course, my first experience with the US justice system. So I'm confused. I'm a bit frustrated. I'm annoyed. So I ended up kind of deciding to fight the case because I also noticed that these charges don't really make any sense. Like, there is no law against writing malware. So you're just charging me with these weird crimes. So I'm like, okay, let's just fight it and see what happens.
57:50Okay, so you had two lawyers at the time. That must have been costly. No, so I was actually very lucky and these two great, great lawyers, Marsha Hoffman and Brian Klein, they reached out to me and they were like, we would like to take your case pro bono. And these are like top, top lawyers, the kind that you would want on your side in a cybercrime case. And I remember they reached out to me and they were just like, we just want to take your case for a charge. um you'll obviously have to pay like court fees and filing fees and uh for your flights to and from the courthouse um but other than that like we're not going to charge you for our services and it it just felt like a gift from the heavens it was it was like so much of the the theme behind this uh this story was just random people i'd never met just sort of going out of their way to help me.
58:45And it was just such a surreal experience to have all of these people just coming to my aid out of seemingly nowhere.
58:57Okay, the fight is on. Two powerhouse lawyers ready for action. Marcus, unhappy with the way the justice system is acting and wants to make things right. But it's a federal case. Federal cases are extremely slow. We're talking years for them to finish. He's got to fly back and forth between Wisconsin, where the trial is, and California, where he lives. Flying gets more and more tricky since his visa expired and he's not supposed to be in the country anymore, but he's also not allowed to leave the country and he can't work in the U.S. either. So for a lot of the time, I was kind of wrestling with this internal conflict of like, A, I'm guilty and I did everything they say I did.
59:36But B, I'm also kind of really just fighting, not because I believe I'm innocent, but because I don't feel like this is how the justice system should work. But what really kind of wore me down is just the time. Like, we're talking a year, two years into the case, and I'm, this is like, it's very, very hard to explain how stressful being in a federal case is. Like, it is a level of stress that goes way beyond even the worst like incident response cases I've ever worked and it's daily like every day you just wake up and you're just like is today the day I go to jail like what's happening in my case blah blah blah and it just it wears you down so fast I mean people have committed suicide like there are people in the hacking community who have committed suicide from the the just sheer constant stress of going through that system and i don't think there is anyone who is set up to actually see that through to the end at some point it like it just gets you to the point where you're just like i just i give up and for me i think that was i think it was about like a year and a half maybe a bit more in we had filed a bunch of motions with the judge to get like certain pieces of evidence dismissed and arguing that certain charges weren't correct and all of the motions were denied.
1:01:07So at that point, we're basically starting from zero. We've got to find a new strategy. We're going to be going for like at least another year. And at that point, I was like, you know, I just, I can't do this anymore. So I ended up just pleading guilty.
1:01:23after fighting it for almost two years he switched and gave in and said fine charge me with whatever stupid stuff you want i'm tired of this honestly at that point i was like if i had just gone to jail from the start and spent a year or two in jail it would have been infinitely easier on my mental health than going through this case. So it was a lot, and I just couldn't take it anymore, so I folded. Okay then, guilty on all charges. Well, the case can be closed now, except for one last thing. The court now has to decide what his punishment is. So a sentencing hearing was scheduled. Some early calculations were saying that he could get anywhere from two to eight years in prison.
1:02:14But of course, his lawyers were trying to fight for him to get the least amount of prison time as possible. In my case, their argument was the FBI actually couldn't produce any evidence of Kronos having damaged systems. That's not to say it didn't. I'm sure it did. But they had not produced any evidence. And part of their argument was that we estimate it caused X tens of thousands, I think it was hundreds of thousands in damages. And they could not produce any evidence to back that up. And their sentencing recommendation was based on their claim that I had caused these hundreds of thousands of dollars in damages, which they couldn't prove.
1:02:51So my lawyers had an argument there of, well, if there is damages, where are they? So his sentencing day comes and he heads into the courtroom. So I basically convinced myself from the start that I was going to jail. So I went into that hearing with the belief that I was going to jail. I think you tweeted something too, like, okay, I'm going to jail, and whatever happens, I love you all. Yeah, pretty much. I was sure that I was not leaving that courtroom. The prosecution gave their arguments. His side gave his arguments. the judge listened to it all and came to a decision basically my punishment was sensing me to time served and even when the judge said time served it didn't register because like um they don't it's not like in the movies where they bang the gavel and they're like this is your sentence there's usually they say the sentence and they'll talk a bit about why and then they'll talk about like what happens next and blah blah blah um so he sort of said the sentence and then he kept talking and I'm like okay so I actually didn't really know what time served means so I'm like is that the sentence I don't know and then he's still talking and I'm like I'm waiting for him to say how much jail time and it's not coming and then I think um the hearing went on for maybe 30 40 more minutes and I was still confused at the end I was like I don't actually understand how this system works or what what time served means and I remember my lawyer just being like you're going home and I'm like what and it just it never registered like it didn't register in the courtroom it didn't register when I went home and it still doesn't register now like in the back of my mind I still feel like I have this thing hanging over me and any minute now I'm going to go to jail and it was because I had just convinced myself since the uh the beginning of the case that this ends in me going to jail and because there was never any jail it hasn't ended in my mind so So I've always, like, I've never been able to, like, fully kind of clear that period of my life from my mind.
1:05:03Well, you should take a trip out to Alcatraz, hang out there for an hour, and do, like, some sort of mental cleansing of, okay, I'm here, I did it, now I'm leaving, and it's over. It sounds funny, but that actually might not be a bad idea.
1:05:20The judge seemed to understand all aspects of this case, even before the defense gave their side. People sent in tons of letters saying why Marcus should be free and serve no jail time. The judge read newspaper clippings of how Marcus is a hero in the UK for stopping one of the world's biggest cyber attacks. And one thing the judge had to think about was what is gained by putting him in jail? Because he's already on the good side. he's doing good work and you're just taking him away from doing the good work what what what do you seek to gain uh for putting him in jail and that's actually what the judge's own argument was um i think i suspect the judge had actually made up his mind about the sentence before any of us had made our arguments like he had looked at the he'd looked at the case he'd looked at the totality of the circumstances and he had been like this just doesn't make any sense so i i strongly suspect the judge had already decided to sentence me to no jail time before we even got into the courtroom he basically said that yep he's been he's self-rehabilitated so there's no uh he needs rehabilitation angle um he's stopped one of the largest ransomware attacks in history and he's been doing all of this great cyber security work he's got all of these letters uh um from like various people in the cyber community they wrote in letters uh explaining why they think i shouldn't go to jail and i think like all of that just put together just made a really strong case for for sentencing me to time served time served simply means whatever time you've spent on this case already is enough punishment you're done you can go home now case closed.
1:07:06And you might think he got the best possible outcome here, but the stress of not knowing what's going to happen to you for two years is a lot harder than you realize. To be honest, I'm being 100 % real when I say this. If I could have taken a year or two in jail instead of going through all of that stress, I would have taken it. So WannaCry was one of the worst things that happened to him, yet seemed to also be the very thing that saved him. It's obviously hard to speculate what would have happened had WannaCry not happened, but there is a chance that I would have got sentenced to jail time if it was not for WannaCry.
1:07:48I don't know that for sure, but yeah, I do think WannaCry was this silver lining of at the time it felt horrible, it was like my anonymity's gone, my life has been turned upside down, but then it most likely helped me out in the court case and it helped me come to terms with like learning I guess better social skills and how to how to do public speaking so while at the time when it happened I would say like this was the most terrible thing that happened that far in my life and I had gone through a lot of terrible things but now when I look back I think it was like it led to a lot of important growth that was needed and it helped me out in a lot of scenarios that would have made my life a lot worse had it not happened so I'm not saying i'm like i'm not changing my answer but i'm saying versus like when it was happening i was very adamant that this was the worst thing to happen to me uh but now in hindsight having had like years of and years of personal development i think it it turned out for the better like i think it improved uh me as a person and it bailed me out of potentially going to jail potentially
1:09:06Thank you so much to Marcus Hutchins for coming on the show and finally sharing the story with us. This is such an incredible story. I'm so glad you finally said yes to it. I started this show the year he got arrested and I've dreamed about having him on this whole time. And I get it. He was busy fighting for his life the whole time. and was constantly being bombarded with interview requests. But that's the thing about me. I don't mind waiting eight years to get the story. Take your time. Unwind. Decompress from the craziest time of your life. And then let's talk. It'll still be a really good story when you're ready.
1:09:40This episode was created by me, Control Alt Deluxe, Jack Recider. Our editor is Zero Day Dreamer, Tristan Ledger. Mixing done by Proximity Sound, and our intro music is by the mysterious Breakmaster Cylinder. There are two kinds of people in InfoSec. Those who have taken a production server down and liars. This is Darknet Diaries.
From the publisher
MalwareTech was an anonymous security researcher, until he accidentally stopped WannaCry, one of the largest ransomware attacks in history. That single act of heroism shattered his anonymity and pulled him into a world he never expected.
Sponsors
Support for the show comes from Black Hills Information Security. Black Hills has a variety of penetration assessment and security auditing services they provide customers to help keep improve the security of a company. If you need a penetration test check out www.blackhillsinfosec.com/darknet.
Support for this show comes from Arctic Wolf. Arctic Wolf is the industry leader in security operations solutions, delivering 24x7 monitoring, assessment, and response through our patented Concierge Security model. They work with your existing tools and become an extension of your existing IT team. Visit arcticwolf.com/darknet to learn more.
Support for this show comes from Cloaked, a digital privacy tool. Cloaked offers private email, phone numbers, and virtual credit card numbers. So you can be anonymous online. They also will remove your personal information from the internet. Like home address, SSN, and phone numbers. Listeners get 20% off a Cloaked subscription when they visit https://cloaked.com/darknet. Calling 1-855-752-5625 for a free scan to check if your personal information is exposed!




