Hacker Conversations: Marcus Hutchins and the Journey From the Gray Zone to Redemption
Marcus Hutchins doesnât personally consider himself a hacker â but he accepts the epithet because itâs a widely used term for what he once did.
Born in Ascot, England, he was working as a cyber threat analyst for an LA-based cybersecurity company in 2017 (aged 22), when he became the worldâs hero for finding a kill switch for the particularly virulent and destructive cryptoworm (ransomware spread by a worm) known as WannaCry. The ransomware decryption didnât work, so there was no way to decrypt files once encrypted (it was effectively a wiper). But the worm worked very well, and more than 200,000 computers were affected in around 150 countries in just a few days.
Three months after saving the world, he was arrested by the FBI.
This is the typically convoluted world navigated by a âhackerâ â a world we try to unravel in this series of Hacker Conversations.
The young Marcus Hutchins
Hutchins diverges from many hackers in having no desire to change something; merely an intense desire to understand how it works. âNot knowing more about how something works bothers me,â he explains.
But although he doesnât wish to change the thing he needs to understand, his understanding leads to an appreciation of how things work, or donât work, or arenât supposed to work but do.
âI will literally be like, âOh, I want to see how this electrical system worksâ. And then Iâll be like, âOkay, I understand the electronics; now I want to see how it works on a physical level, and then on a quantum physics levelâ, and I just sort of end up spiraling â just wanting to know more and more about how any specific system works.â
This intensity may partially be an effect of neurodiversity, a very common condition among natural hackers. âIf I get interested enough in a task, I find it very easy to just commit a lot of time to that task. So of course, the flip side of that is, if Iâm not interested in said task, I am basically useless.â
The natural effect of this type of polarization is a deep understanding of some subjects, but little knowledge of others. He was given his first computer at 13. This was something that interested him. In the next few years, he taught himself VB, PHP, C, C++, and Assembly. But at a cost to his other school studies.
âI was just this very young kid with too many skills in a certain area and no productive outlet for them. Academic qualifications were already out of the window. I was basically just a writer of code.â
Like attracts like. This combination gravitated toward other coders with a similar lack of academic qualification or predefined direction. âI started getting involved on cybercrime forums quite early on. My skill was primarily coding, so I ended up writing hacks rather than doing hacking.â This explains his reluctance to think of himself as a hacker â he worked with and perhaps for hackers, but was never personally engaged in hacking.
âI got involved in selling software for hackers to use, either to assist in hacks or to perform hacks. So, I ended up becoming part of a cybercrime group where I was their professional malware developer â my job was to maintain the back doors and the code responsible for subverting antiviruses and bypassing security systems.â
This journey started while he was still at school. He occasionally shut down the school computers, just briefly, and just for fun. In 2013, he started to write an anonymous blog called MalwareTech focused on how malware works, and included within it proof of concepts. The blog became popular for both cybersecurity professionals and cybercriminals; but the criminals were willing to pay for his proof of concepts â and he didnât stop them.
At no point did he consciously decide to be âbadâ. âThere was never a distinct line where I could think, âThis is OK, but that isnâtâ. Things arenât black and white â itâs all just a big scale of gray,â he comments. To begin with, he had a skill, and he was just selling that skill. There was a disconnect between what he did with his skill, and what they did with his skill. âFrom my perspective, Iâm writing some code, which I then sell to a person, and then I donât see it again after that. Thatâs just kind of the way that scene works.â
He was still a young kid. âI didnât really think about, âWhere does the code go after I sell it? What do they do with it?â I wasnât stupid, and I could guess it wasnât anything good. But not directly knowing what was happening removed a lot of the psychological barrier that would have existed if I was doing it myself â like robbing a bank or mugging someone. That would be very clear: I am doing something bad here that hurts another person.â
At the time, he felt it was more like re-selling his kitchen knife. âWhat are they going to do with my kitchen knife? Are they going to cut vegetables or cut a person? Just the lack of any clean knowledge of what is actually going on allows you to emotionally distance yourself for a bit.â
But the distancing didnât hold. Over time he got too close to some of the organizations who were using his code, and he began to see the harm his code was causing. âI just didnât like knowing that I was responsible for those kinds of things. I decided to cut ties and look for a legitimate job.â
The maturing Marcus Hutchins hero
There is an amorality in the actions of most young hackers. But there comes a point where these young hackers make a conscious choice between morality (the white) and immorality (the black). Hutchins was no different; and this was that time.
For some, the decision to choose morality is based on parental upbringing; for others it is a religious background. For Hutchins it seems to be an innate understanding of the difference and choice between good and bad that grew with his own growing maturity. He chose to eschew the harmful side of hacking.
Just as MalwareTech had introduced him to the criminal element, so it had also introduced him to cybersecurity professionals. In 2016 he found a position as a research and development lead for a firm in Los Angeles; and moved to the US. This was a year before the original WannaCry outbreak, and he was now a legitimate cybersecurity professional.
Remember the effect of his neurodiversity â if he found a task interesting, he was capable of deep focus. WannaCry interested him. âWannaCry was a big deal at the time. Unrelated organizations were going down all round the country, and nobody really knew why. That sort of interested me, because it was nothing like anything I had seen before.â
WannaCry was based on a leaked NSA exploit called EternalBlue which scanned the internet for any computer with an available SMB port, and opened a backdoor called DoublePulsar. The hackers used these to locate accessible targets and then to deliver their own ransomware. The result was ransomware that copied itself, unaided, from computer to computer in a chain reaction across the internet. The exploit originated from the NSA and worked. The ransomware was coded by the hackers and only partly worked: the encryption worked, but the decryption failed â making it a ferociously aggressive and destructive wiper.
âAs Iâm analyzing this malware, I noticed thereâs an unregistered domain in the code.â This, in itself, is not unusual. Researchers who find such domains within malware register them, because it helps to monitor and understand the malware. So, Hutchins registered iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea dot com for $10.69.
Able to see what was happening, he found the site was getting hammered, receiving tens of thousands of queries every couple of minutes. âSo, Iâm looking for a way to understand what itâs doing and stop it, when I learn that WannaCry itself had stopped. The domain was the kill switch simply by being on the internet and responding to the queries with a 200 status codeâ [the way a receiving web server tells the source the message has been received].
Nobody really understands why the malware was coded this way; why the mere existence of a web server at that strange address should stop it working. There are many theories and suggestions; but the reason doesnât really matter. âIt basically deactivates the thing. So, all we need do is maintain a web server with the web address pointed to that web server, and as long as that server does not go down, the malware is not able to spread.â
From hero to villain
Three months later, still in LA, the FBI arrested him. âIt was basically for the stuff I had been doing earlier. They didnât find out about it until long after the fact, but for whatever reason, they decided they still wanted to prosecute me. I ended up getting sent through the US court system for something that I had previously done and had since stopped doing. I spent the next three years after WannaCry fighting this case in court related to conduct that occurred long before stopping WannaCry.â
He was held in the Nevada Southern Detention Center pending trial. But after one week in prison, Tarah M. Wheeler (currently CSO at the TPO Group, member of the board of directors at EFF, and CISO at Red Queen Technologies â among other positions) stepped forward and posted $30,000 cash bail to gain him temporary release.
The court case lasted two years, culminating with Hutchins pleading guilty to computer hacking and advertising a wiretapping device (two of the many charges raised against him). The judge, however, apparently recognized that he had already rehabilitated himself (perhaps also taking account of the WannaCry incident), and sentenced him to one year probation â after which he decided to stay in the US.
The history of Hutchins, from passive bad guy to active good guy, is uncommon. It provides an unusual slant on the saying âno good deed goes unpunishedâ. In this case, no bad deed goes unpunished, literally. His early dubious work on MalwareTech led to his prosecution by the FBI. But at the same time, it raised his profile as a person who knows about malware.
Similarly, the usual meaning of âno good deed goes unpunishedâ is equally true. It is more than possible that the publicity he received over WannaCry allowed the FBI to connect his name to the originally anonymous MalwareTech blog â and proceed to prosecute the man behind the blog.
He still publishes MalwareTech â and it has become his pseudonym â but it has been overhauled to be more about cybersecurity than cybercriminality. Last year he received a call from a contact asking if he would like to work for his firm. Hutchins was effectively headhunted on the strength of his reputation. He is now, at age 32, Principal Threat Researcher at Expel, doing a mix of cyber threat intelligence and writing blog posts about malware â so, basically the same old thing, but now fully legitimately.
Related: Hacker Conversations: Katie Paxton-Fear Talks Autism, Morality and Hacking
Related: Hacker Conversations: Alex Hall, One-Time Fraudster
Related: Hacker Conversations: Kunal Agarwal and the DNA of a Hacker
Related: Hacker Conversations: McKenzie Wark, Author of A Hacker Manifesto
How it works
Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content â general knowledge won't be enough. Score 70+ to count toward your certificate.
Questions are cached â you'll always get the same 5 for this article.