Threat Picture
Latest Cybersecurity News

John Hammond: Making Malware Research a Public Lesson

From military classrooms to ransomware investigations, he turned the work of finding and explaining threats into lessons anyone could watch.
By Charles Joseph · Updated
Share
Share
Copy URL

When a ransomware wave hit more than a thousand businesses over the July 4th weekend of 2021, one of the first public warnings came not from a government agency but from a security researcher named John Hammond.

Hammond is two people at once. By day he's a threat researcher at Huntress, one of the firms reporters turn to when a file-transfer tool or a remote-access product starts getting exploited at scale. The rest of the time he's a YouTuber with more than two million subscribers, walking viewers through code, capture-the-flag puzzles and the latest threats for free.

He got there by teaching himself from other people's videos, and deciding the best way to learn was to make his own.

John Hammond at a Glance

  • Hammond's father taught him HTML, CSS and JavaScript and how to run web servers, and he filled in the rest by Googling and watching YouTube tutorials.
  • He went to the United States Coast Guard Academy, where the emphasis on whether code could survive an attack introduced him to vulnerabilities, exploits and CVEs.
  • His YouTube channel dates to February 2011, and for years it grew slowly.
  • As an instructor at the Department of Defense Cyber Training Academy, he taught the Cyber Threat Emulation course: offensive Python, PowerShell and the adversarial mindset, to civilians and military members.
  • At Huntress he was among the first to reveal the Kaseya supply-chain ransomware attack in July 2021, and reporters have quoted him on mass-exploitation events since, from ConnectWise and Cleo to Windows Defender zero-days.
  • He's written challenges for picoCTF and DEF CON competitions, spoken at conferences and the Naval Academy, and teaches through Just Hacking Training.
  • As of October 2026 his channel has 2.17 million subscribers, nearly 1,900 videos and 93 million views.
Sponsored

The Life of John Hammond

Learning From Dad

Hammond's education in computers started at home. His father taught him HTML, CSS and JavaScript, then showed him how to manage web servers like Apache and Nginx.

Everything after that came from the internet. "The way that I was learning way back was through Googling," he told The Cyber Express in 2024. "I was looking online and watching videos on YouTube on how to code a program and work through tutorials."

He was building things before he had any reason to think about breaking them. That changed when he went to college.

The Coast Guard Academy

Hammond went to one of the American service academies, the Coast Guard Academy, and found an institution that cared less about whether a program worked than whether it could take a punch.

"It's cool that you made this thing, but is it battle-tested? Is it safe? Is it sturdy? Can it be beaten up?" he recalled. "That introduced me to vulnerabilities and exploits and CVE."

He liked the moral clarity of it. Defending against adversaries, he said, felt like "a good versus evil mentality," and he decided that was the field for him.

Sponsored

Silly Videos

The YouTube channel began as a study aid. "I've heard people say the best way to become a master of something or to get better at it is to try to teach it to others," Hammond said. "So, I thought, I can make some silly videos and showcase what I'm learning."

By his own account, the oldest videos on the channel go back to around 2009 or 2011. "It's slow growth," he said. "I never expected it to become what it is today."

What he made was programming tutorials and walkthroughs of capture-the-flag challenges: the puzzle competitions where players break deliberately vulnerable software. He went from solving them to writing them, developing challenges for picoCTF and competitions at DEF CON, and speaking at the SANS Holiday Hack Challenge, the yearly KringleCon.

Teaching the Pentagon

Before Huntress, Hammond taught at the Department of Defense Cyber Training Academy, where he was the instructor for the Cyber Threat Emulation course.

The job was to teach civilian and military students to think like the attacker: offensive Python, PowerShell and other scripting languages, plus the adversarial mindset that goes with them. He also spoke at BSidesNoVA and to students at the US Naval Academy.

Along the way he collected an unusual stack of certifications, from Security+ and the CEH to Offensive Security's OSCP, OSWE, OSEP and OSED, the trio that make up the OSCE3.

The July 4th Weekend

On Friday, July 2, 2021, hackers linked to the REvil ransomware gang exploited zero-day flaws in Kaseya's VSA management software and used its update mechanism to push ransomware through managed service providers to their customers.

Hammond, then a senior security researcher at Huntress Labs, was among the first to reveal the attack. He said about 30 managed service providers had been hit and that the ransomware had spread to "well over" 1,000 businesses, TechCrunch reported. REvil demanded $70 million for a universal decryptor.

It was the moment Hammond became a go-to name for reporters covering mass hacks. When the Log4j flaw landed that December, his warnings about what it could've unleashed made headlines again.

Sponsored

Embarrassingly Easy

The calls kept coming. In February 2024 a maximum-severity authentication bypass in ConnectWise ScreenConnect, a remote-access tool used by IT providers, went under attack. Hammond reported exploitation was "current and active," with attackers moving to "more focused post-exploitation and persistence mechanisms."

"We are seeing adversaries already deploy Cobalt Strike beacons and even install a ScreenConnect client onto the affected server," he said. Huntress CEO Kyle Hanslovan was blunter, saying he couldn't sugarcoat how bad it was.

That December, Huntress found hackers "exploiting this software en masse" in Cleo's file-transfer products, whose October patch hadn't fixed the bug. Huntress counted at least 24 compromised businesses among the more than 1,700 Cleo servers it protected, and Hammond said the victims included "various consumer product companies, logistics and shipping organizations, and food suppliers."

Two Million Subscribers

Meanwhile the silly videos had become one of the largest security channels on YouTube. By October 2026 John Hammond had 2.17 million subscribers, nearly 1,900 videos and 93 million views under a one-line mission statement: "Free Cybersecurity Education and Ethical Hacking."

He also teaches as an instructor at Just Hacking Training, a platform that advertises "courseware by humans," and keeps a GitHub account whose bio reads, in full, "Hacker. Friend."

The Tug-of-War

In April 2026, a researcher calling themselves Chaotic Eclipse published exploit code for three unpatched Windows Defender flaws after a dispute with Microsoft, and criminals began using them in real attacks.

Hammond's reaction summed up a career spent on the defensive side of a very public fight. "With these being so easily available now, and already weaponized for easy use, for better or for worse I think that ultimately puts us in another tug-of-war match between defenders and cybercriminals," he told TechCrunch.

"Scenarios like these cause us to race with our adversaries," he added, "especially now as it is just ready-made attacker tooling."

Sponsored

John Hammond: Making Hackers Earn It

His bio describes the day job as making hackers earn their access and helping tell the story. The second half is the part he does for everyone, every week, for nothing.

He still works the incidents and still records the walkthroughs, with two million people watching over his shoulder.

The kid who learned from YouTube tutorials became the teacher on the screen.

QUOTE:

"Amateurs hack systems, professionals hack people."