Marcus Hutchins: The WannaCry Kill Switch and the Kronos Case
On a Friday afternoon in May 2017, a 22-year-old came back from the chip shop in a Devon seaside town, sat down at the computer in his bedroom and spent $10.69 on a web address. Within hours, the worst cyberattack the world had ever seen stopped doing damage.
Marcus Hutchins, known online as MalwareTech, became the "accidental hero" of WannaCry overnight. He gained 100,000 Twitter followers in a day, strangers bought him drinks in the local pub and a restaurant offered him free pizza for a year.
Three months later, at the Las Vegas airport on his way home from Def Con, two FBI agents sat him down and asked about a banking trojan called Kronos. He knew the name.
Marcus Hutchins at a Glance
- Born in 1994, Hutchins moved with his family from Bracknell, near London, to a cattle farm in rural Devon when he was nine, and taught himself to code before he was a teenager.
- By 15 he was bragging on hacker forums about a botnet of more than 8,000 machines and running a hosting service that advertised itself as a home for "all illegal sites".
- Working with a partner he knew only as Vinny, he wrote the UPAS Kit rootkit, on sale by 2012, and then the Kronos banking trojan, which Vinny priced at $7,000.
- He drifted away from Vinny, started the MalwareTech blog and learned to track botnets from the inside, which earned him a six-figure job at the Los Angeles firm Kryptos Logic.
- On May 12, 2017, Hutchins registered a domain he found in WannaCry's code. It turned out to be a kill switch, and within hours the global attack stopped doing harm.
- On August 2, 2017, the FBI arrested him in Las Vegas on a six-count indictment over Kronos. Bail was set at $30,000.
- He pleaded guilty to two counts in the spring of 2019, facing up to 10 years, and on July 26, 2019, a judge sentenced him to time served and one year of supervised release.
- In October 2025, the security firm Expel announced a day-to-day partnership with Hutchins on its new threat intelligence program.
The Life of Marcus Hutchins
Hutchins's Early Years
Marcus Hutchins was born in 1994 and spent most of his childhood in a stone house on a cattle farm in remote Devon, a few minutes from the west coast of England. His mother, Janet, was a nurse from Scotland; his father, Desmond, was a social worker from Jamaica.
He had no interest in football and preferred surfing in the freezing Atlantic, and he took up surf lifesaving, a competitive form of lifeguarding, winning medals at the national level.
Computers were the real obsession. Bored in computer class, he learned to bypass the school's restrictions to install games, and by his early teens he'd found his way onto hacking forums.
The Teenage Malware Writer
The forum that mattered was HackForums, where the price of respect was owning a botnet. At 15, Hutchins was running one of more than 8,000 computers, infected mostly through fake files he'd seeded on BitTorrent sites.
He also went into business, renting servers and selling hosting to other forum members under the name Gh0sthosting, which advertised that "all illegal sites" were allowed. At 16 he was approached by a more serious client, a figure he'd only ever know as Vinny.
Vinny wanted a professional rootkit to sell on marketplaces like Exploit.in, with the profits split down the middle. After nearly nine months of work, UPAS Kit went on sale in the summer of 2012, and the bitcoin commissions began.
Then came the request that'd define Hutchins's life: a banking trojan with web injects, the feature that lets malware rewrite a bank's login page inside the victim's browser. Vinny named it Kronos, after the Greek titan, and listed it at an ambitious $7,000.
Kronos sold modestly to demanding customers, and after a year of nonstop updates Hutchins fell behind. The payments stopped, and the partnership faded away.
MalwareTech
What came next was a year of quiet rehabilitation. Hutchins started a blog under the name MalwareTech, dissecting other people's malware, and soon had more than 10,000 regular readers who had no idea the author had written malware himself.
He went after the biggest botnets in the wild, Kelihos and Necurs, wrote code that spoke Kelihos's peer-to-peer language so he could spy on it from inside, and published a public tracker mapping hundreds of thousands of infected machines.
That caught the eye of Salim Neino, CEO of a small Los Angeles security firm called Kryptos Logic. Neino offered the anonymous blogger $10,000 to build a Kelihos tracker, then a job with a six-figure salary, and Hutchins thought he was joking.
In his first months at Kryptos Logic he burrowed into Necurs, Dridex and Emotet, and on Twitter, behind the avatar of a Persian cat in sunglasses, he became an elite malware whisperer.
The Kill Switch
On Friday, May 12, 2017, a worm later known as WannaCry tore across the internet using EternalBlue, an NSA exploit leaked a month earlier by the Shadow Brokers. It encrypted files, demanded bitcoin and spread on its own to any unpatched Windows machine it could reach.
In England it hit 81 NHS trusts and around 600 GP surgeries, forcing hospitals to cancel operations and divert ambulances. Telefónica, Deutsche Bahn and FedEx were hit too, and Europol would count more than 200,000 victims in at least 150 countries.
Hutchins was on a week off. At around 2:30 pm he got back from the fish-and-chip shop in Ilfracombe to find the internet on fire, and a hacker friend known as Kafeine sent him a sample within minutes.
Running it in a test environment, he noticed that before encrypting anything, the malware tried to reach a long, gibberish domain name nobody had registered. So he registered it at four seconds past 3:08 pm, for $10.69, hoping to sinkhole the traffic and map the infections.
At 6:30 pm, Kafeine sent him a tweet from researcher Darien Huss: "Execution fails now that domain has been sinkholed." The code checked whether it could reach that domain before doing any damage, and if it could, it quit. Hutchins had thrown a kill switch without knowing it was there.
He wrote it up the next day under the title How to Accidentally Stop a Global Cyber Attacks, and told the Associated Press, "I'm definitely not a hero."
Hero to Defendant
Nearly three months later, Hutchins let himself enjoy the rock-star treatment at Def Con in Las Vegas. On August 2, 2017, he was waiting for his flight home when two agents flashed FBI badges, asked friendly questions about his job and then, 11 minutes in, brought up Kronos.
A grand jury in Wisconsin had returned a six-count indictment three weeks earlier, charging him with conspiracy to commit computer fraud and abuse and with advertising and distributing an interception device, over conduct between July 2014 and July 2015. Bail was set at $30,000.
The hacker community rallied. Lawyers Brian Klein and Marcia Hofmann took the case for free, Hutchins pleaded not guilty at his arraignment in Milwaukee, and he was allowed to live in Los Angeles while the case dragged on.
Within a month, Brian Krebs had dug up his old HackForums posts, and the picture got more complicated. In June 2018, prosecutors returned a 10-count superseding indictment that added UPAS Kit and a charge of lying to the FBI.
One early theory, that Hutchins had written WannaCry himself, died on its own: the US blamed North Korea for the attack in December 2017 and charged a North Korean programmer, Park Jin Hyok, over it in September 2018.
Time Served
In April 2019, Hutchins announced that he was pleading guilty to two of the charges, and the plea was entered in court on May 2: conspiracy to commit computer fraud, and advertising a device used to intercept electronic communications. According to the Justice Department, each count carried up to five years in prison.
Sentencing came on July 26, 2019, in Milwaukee, before Judge J.P. Stadtmueller, a 77-year-old with a reputation for unpredictable sentences. Hutchins slipped into the courthouse two hours early to avoid the press.
The judge weighed the teenager who wrote Kronos against the researcher who stopped WannaCry and concluded: "There are just too many positives on the other side of the ledger." The sentence was time served plus one year of supervised release.
Stadtmueller even said Hutchins might deserve a full pardon, which the court couldn't grant, and warned that the conviction would make it hard for him to come back to the US. When Wired published his full story in May 2020 as The Confessions of Marcus Hutchins, the Hacker Who Saved the Internet, he'd overstayed his visa and was taking what looked like a last walk along the Los Angeles beaches.
Hutchins Today
Hutchins kept doing the work: writing, reverse engineering, podcasts and conference stages, and a role as one of the more thoughtful public voices on how cybercriminals get made, and unmade.
In October 2025, the managed detection and response firm Expel announced a day-to-day partnership with Hutchins for its new Expel Intel research program, where he focuses on malware analysis and threat hunting. The pitch was simple: he's seen the threat landscape from both sides.
Marcus Hutchins: Both Sides of the Ledger
Most hacker stories run in one direction, from mischief to prison or from prison to redemption. Hutchins lived his in the wrong order, hero first and defendant second, with a secret he carried through the whole of his fame.
The judge's ledger is the right way to read him. On one side sits a teenager who sold banking malware for bitcoin; on the other, the researcher who bought the world a few badly needed hours for $10.69 and has spent every year since on defense.
He still says he isn't a hero. The internet, for one afternoon in 2017, would beg to differ.
QUOTE:
"Amateurs hack systems, professionals hack people."