Marcus Hutchins doesn’t personally consider himself a hacker – but he accepts the epithet because it’s a widely used term for what he once did.
Born in Ascot, England, he was working as a cyber threat analyst for an LA-based cybersecurity company in 2017 (aged 22), when he became the world’s hero for finding a kill switch for the particularly virulent and destructive cryptoworm (ransomware spread by a worm) known as WannaCry. The ransomware decryption didn’t work, so there was no way to decrypt files once encrypted (it was effectively a wiper). But the worm worked very well, and more than 200,000 computers were affected in around 150 countries in just a few days.
Three months after saving the world, he was arrested by the FBI.
This is the typically convoluted world navigated by a ‘hacker’ – a world we try to unravel in this series of Hacker Conversations.
The young Marcus Hutchins
Hutchins diverges from many hackers in having no desire to change something; merely an intense desire to understand how it works. “Not knowing more about how something works bothers me,” he explains.
But although he doesn’t wish to change the thing he needs to understand, his understanding leads to an appreciation of how things work, or don’t work, or aren’t supposed to work but do.
“I will literally be like, ‘Oh, I want to see how this electrical system works’. And then I’ll be like, ‘Okay, I understand the electronics; now I want to see how it works on a physical level, and then on a quantum physics level’, and I just sort of end up spiraling – just wanting to know more and more about how any specific system works.”
This intensity may partially be an effect of neurodiversity, a very common condition among natural hackers. “If I get interested enough in a task, I find it very easy to just commit a lot of time to that task. So of course, the flip side of that is, if I’m not interested in said task, I am basically useless.”
The natural effect of this type of polarization is a deep understanding of some subjects, but little knowledge of others. He was given his first computer at 13. This was something that interested him. In the next few years, he taught himself VB, PHP, C, C++, and Assembly. But at a cost to his other school studies.
“I was just this very young kid with too many skills in a certain area and no productive outlet for them. Academic qualifications were already out of the window. I was basically just a writer of code.”
Like attracts like. This combination gravitated toward other coders with a similar lack of academic qualification or predefined direction. “I started getting involved on cybercrime forums quite early on. My skill was primarily coding, so I ended up writing hacks rather than doing hacking.” This explains his reluctance to think of himself as a hacker – he worked with and perhaps for hackers, but was never personally engaged in hacking.
“I got involved in selling software for hackers to use, either to assist in hacks or to perform hacks. So, I ended up becoming part of a cybercrime group where I was their professional malware developer – my job was to maintain the back doors and the code responsible for subverting antiviruses and bypassing security systems.”
This journey started while he was still at school. He occasionally shut down the school computers, just briefly, and just for fun. In 2013, he started to write an anonymous blog called MalwareTech focused on how malware works, and included within it proof of concepts. The blog became popular for both cybersecurity professionals and cybercriminals; but the criminals were willing to pay for his proof of concepts – and he didn’t stop them.
At no point did he consciously decide to be ‘bad’. “There was never a distinct line where I could think, ‘This is OK, but that isn’t’. Things aren’t black and white – it’s all just a big scale of gray,” he comments. To begin with, he had a skill, and he was just selling that skill. There was a disconnect between what he did with his skill, and what they did with his skill. “From my perspective, I’m writing some code, which I then sell to a person, and then I don’t see it again after that. That’s just kind of the way that scene works.”
He was still a young kid. “I didn’t really think about, ‘Where does the code go after I sell it? What do they do with it?’ I wasn’t stupid, and I could guess it wasn’t anything good. But not directly knowing what was happening removed a lot of the psychological barrier that would have existed if I was doing it myself – like robbing a bank or mugging someone. That would be very clear: I am doing something bad here that hurts another person.”
At the time, he felt it was more like re-selling his kitchen knife. “What are they going to do with my kitchen knife? Are they going to cut vegetables or cut a person? Just the lack of any clean knowledge of what is actually going on allows you to emotionally distance yourself for a bit.”
But the distancing didn’t hold. Over time he got too close to some of the organizations who were using his code, and he began to see the harm his code was causing. “I just didn’t like knowing that I was responsible for those kinds of things. I decided to cut ties and look for a legitimate job.”
The maturing Marcus Hutchins hero
There is an amorality in the actions of most young hackers. But there comes a point where these young hackers make a conscious choice between morality (the white) and immorality (the black). Hutchins was no different; and this was that time.
For some, the decision to choose morality is based on parental upbringing; for others it is a religious background. For Hutchins it seems to be an innate understanding of the difference and choice between good and bad that grew with his own growing maturity. He chose to eschew the harmful side of hacking.
Just as MalwareTech had introduced him to the criminal element, so it had also introduced him to cybersecurity professionals. In 2016 he found a position as a research and development lead for a firm in Los Angeles; and moved to the US. This was a year before the original WannaCry outbreak, and he was now a legitimate cybersecurity professional.
Remember the effect of his neurodiversity – if he found a task interesting, he was capable of deep focus. WannaCry interested him. “WannaCry was a big deal at the time. Unrelated organizations were going down all round the country, and nobody really knew why. That sort of interested me, because it was nothing like anything I had seen before.”
WannaCry was based on a leaked NSA exploit called EternalBlue which scanned the internet for any computer with an available SMB port, and opened a backdoor called DoublePulsar. The hackers used these to locate accessible targets and then to deliver their own ransomware. The result was ransomware that copied itself, unaided, from computer to computer in a chain reaction across the internet. The exploit originated from the NSA and worked. The ransomware was coded by the hackers and only partly worked: the encryption worked, but the decryption failed – making it a ferociously aggressive and destructive wiper.
“As I’m analyzing this malware, I noticed there’s an unregistered domain in the code.” This, in itself, is not unusual. Researchers who find such domains within malware register them, because it helps to monitor and understand the malware. So, Hutchins registered iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea dot com for $10.69.
Able to see what was happening, he found the site was getting hammered, receiving tens of thousands of queries every couple of minutes. “So, I’m looking for a way to understand what it’s doing and stop it, when I learn that WannaCry itself had stopped. The domain was the kill switch simply by being on the internet and responding to the queries with a 200 status code” [the way a receiving web server tells the source the message has been received].
Nobody really understands why the malware was coded this way; why the mere existence of a web server at that strange address should stop it working. There are many theories and suggestions; but the reason doesn’t really matter. “It basically deactivates the thing. So, all we need do is maintain a web server with the web address pointed to that web server, and as long as that server does not go down, the malware is not able to spread.”
From hero to villain
Three months later, still in LA, the FBI arrested him. “It was basically for the stuff I had been doing earlier. They didn’t find out about it until long after the fact, but for whatever reason, they decided they still wanted to prosecute me. I ended up getting sent through the US court system for something that I had previously done and had since stopped doing. I spent the next three years after WannaCry fighting this case in court related to conduct that occurred long before stopping WannaCry.”
He was held in the Nevada Southern Detention Center pending trial. But after one week in prison, Tarah M. Wheeler (currently CSO at the TPO Group, member of the board of directors at EFF, and CISO at Red Queen Technologies – among other positions) stepped forward and posted $30,000 cash bail to gain him temporary release.
The court case lasted two years, culminating with Hutchins pleading guilty to computer hacking and advertising a wiretapping device (two of the many charges raised against him). The judge, however, apparently recognized that he had already rehabilitated himself (perhaps also taking account of the WannaCry incident), and sentenced him to one year probation – after which he decided to stay in the US.
The history of Hutchins, from passive bad guy to active good guy, is uncommon. It provides an unusual slant on the saying ‘no good deed goes unpunished’. In this case, no bad deed goes unpunished, literally. His early dubious work on MalwareTech led to his prosecution by the FBI. But at the same time, it raised his profile as a person who knows about malware.
Similarly, the usual meaning of ‘no good deed goes unpunished’ is equally true. It is more than possible that the publicity he received over WannaCry allowed the FBI to connect his name to the originally anonymous MalwareTech blog – and proceed to prosecute the man behind the blog.
He still publishes MalwareTech – and it has become his pseudonym – but it has been overhauled to be more about cybersecurity than cybercriminality. Last year he received a call from a contact asking if he would like to work for his firm. Hutchins was effectively headhunted on the strength of his reputation. He is now, at age 32, Principal Threat Researcher at Expel, doing a mix of cyber threat intelligence and writing blog posts about malware – so, basically the same old thing, but now fully legitimately.
Related: Hacker Conversations: Katie Paxton-Fear Talks Autism, Morality and Hacking
Related: Hacker Conversations: Alex Hall, One-Time Fraudster
Related: Hacker Conversations: Kunal Agarwal and the DNA of a Hacker
Related: Hacker Conversations: McKenzie Wark, Author of A Hacker Manifesto
