Earlier quoted context omitted.
> TouchMe is MalwareTech, 0 doubt https://twitter.com/touchmymalware If I was a bad man in the security profession who was certain he was anonymous, I'd point to someone else who was a security professional on twitter when I vanished too. It just y'know, wouldn't have been me.
That tweet was in 2013 however.
Researcher Who Stopped WannaCry Ransomware Detained in US After Def Con
231–240 of 268 posts
Re: Researcher Who Stopped WannaCry Ransomware Detained in US After Def Con
#232Earlier quoted context omitted.
That tweet was in 2013 however.
If you tweet and stop using an account that is what happens and that was a shady group of people in 2013.
I used to talk to this guy on a malware dev IRC on a daily basis, he started a blog "TouchMyMalware" which eventually evolved into Malwaretech.
This is all easily verifiable with google and archive.org.
And lol, apparently some twitter user dug up logs of him offering to sell me a rootkit for $20k https://twitter.com/jeremiahg/status/893207272154734592
Re: Researcher Who Stopped WannaCry Ransomware Detained in US After Def Con
#233Earlier quoted context omitted.
Indicted: "Hutchins, who is indicted with another un-named co-defendant, stands accused of six counts of hacking-related crimes as a result of his alleged involvement with Kronos. “Defendent Marcus Hutchins created the Kronos malware,”" https://www.theguardian.com/technology/2017/aug/03/researche...
Just to make this all stranger: @MalwareTechBlog Anyone got a kronos sample? 10:26 AM - 13 Jul 2014 https://twitter.com/MalwareTechBlog/status/48837379416825446... edit: Weird, read the Indictment. This day is specifically called out (although not this post). edit #2: The video mentioned in the indictment: https://www.youtube.com/watch?v=IZPzMzK78tc&feature=youtu.be
Re: Researcher Who Stopped WannaCry Ransomware Detained in US After Def Con
#234Earlier quoted context omitted.
Competing against a US corporation is not a crime and neither is a False name on Facebook.
Using a false name on facebook is against their ToS, is it not? There was a story within the last week about how violating ToS is arguably a felony in the US.
Re: Researcher Who Stopped WannaCry Ransomware Detained in US After Def Con
#235Why in heaven's name did he travel to the US?
There is an annual security focused convention going on this week called "Defcon" that many security focused engineers typically attend. Since wannacry was a big thing that happened between this year's con and last year's con, and because Hutchins is a security researcher, I'm sure he was invited to attend if not give a talk.
Why travel to the US if just three years ago, he broke multiple US cyber laws?
Answer: because he's not as smart as he thought.
Re: Researcher Who Stopped WannaCry Ransomware Detained in US After Def Con
#236yeaaah let us arrest the good guys...
The indictment shows he broke six US cyber laws in 2014 in connection to the Kronos malware, which he created.
Re: Researcher Who Stopped WannaCry Ransomware Detained in US After Def Con
#237Re: Researcher Who Stopped WannaCry Ransomware Detained in US After Def Con
#238Earlier quoted context omitted.
I don't think he directly ran his own IRC, it was a "in partnership with another organization" sort of thing.
Here it is > For anyone still into IRC, MalwareTech has partnered with sigterm.no to launch a new IRC network. It’s still fairly new so don’t expect an instant response, but everyone is welcome (socializing or just asking for help). https://www.malwaretech.com/2014/10/new-irc-launc.html
Re: Researcher Who Stopped WannaCry Ransomware Detained in US After Def Con
#239Earlier quoted context omitted.
Shouldn't we all avoid US conferences? Half the people have some day done something which in a generic way is "against US interests" (from a false name on Facebook to competing against a US corp to starting a petition or a secure app). I personally don't go to US conferences or visit US customers, simply because of TSA (same for Japan and China; Europe has a better track record). If you have a choice, it's not really…
Competing against a US corporation is not a crime and neither is a False name on Facebook.
Re: Researcher Who Stopped WannaCry Ransomware Detained in US After Def Con
#240Reading the indictment, it seems like his partner ratted him out. Curious though, the indictment seems to list the redacted partner as doing most of the incriminating things (posting a video demonstration, advertising the sale on AlphaBay, etc), it merely accused Marcus as being the author and co-conspirator. I wonder if his partner/friend got caught, and plea bargained to turn state's evidence against Marcus.
In other words, AlphaBay goes down, FBI analyses information and determines Mr. Redacted was responsible for Kronos. They arrest him, and in interrogation, he decides to blame someone else for anything they can't actually prove is him directly.