{"id":180029,"date":"2017-08-03T19:02:00","date_gmt":"2017-08-04T00:02:00","guid":{"rendered":"https:\/\/www.panix.com\/~msaroff\/40years\/2017\/08\/03\/this-is-profoundly-weird\/"},"modified":"2017-08-03T19:02:00","modified_gmt":"2017-08-04T00:02:00","slug":"this-is-profoundly-weird","status":"publish","type":"post","link":"https:\/\/www.panix.com\/~msaroff\/40years\/2017\/08\/03\/this-is-profoundly-weird\/","title":{"rendered":"This is Profoundly Weird"},"content":{"rendered":"<div>Marcus Hutchins, a white hat hacker who shut down the WannaCry ransomware, was <a href=\"https:\/\/motherboard.vice.com\/en_us\/article\/ywp8k5\/researcher-who-stopped-wannacry-ransomware-detained-in-us-after-def-con\">just arrested by the FBI, and charged with creating and distributing a banking Trojan 3 years ago<\/a>:<\/div>\n<blockquote><p><span style=\"color: blue;\">On Wednesday, US authorities detained a researcher who goes by the handle MalwareTech, best known for stopping the spread of the WannaCry ransomware virus. <\/p>\n<p>In May, <a href=\"https:\/\/motherboard.vice.com\/en_us\/article\/4xkqqg\/a-massive-ransomware-explosion-is-hitting-targets-all-over-the-world\">WannaCry infected hospitals<\/a> in the UK, a Spanish telecommunications company, and other targets in Russia, Turkey, Germany, Vietnam, and more. Marcus Hutchins, a researcher from cybersecurity firm Kryptos Logic, inadvertently stopped WannaCry in its tracks by registering a specific website domain included in the malware&#8217;s code. <\/p>\n<p>Hutchins was arrested for <a href=\"https:\/\/motherboard.vice.com\/en_us\/article\/pagn7v\/malwaretech-wannacry-indictment-kronos-malware\">allegedly creating the Kronos banking malware<\/a>. <\/p>\n<p>Motherboard verified that a detainee called Marcus Hutchins, 23, was being held at the Henderson Detention Center in Nevada early on Thursday. A few hours after, Hutchins was moved to another facility, according to a close personal friend. <\/p>\n<p>The friend told Motherboard they &#8220;tried to visit him as soon as the detention centre opened but he had already been transferred out.&#8221; Motherboard granted the source anonymity due to privacy concerns. <\/p>\n<p>&#8220;I&#8217;ve spoken to the US Marshals again and they say they have no record of Marcus being in the system. At this point we&#8217;ve been trying to get in contact with Marcus for 18 hours and nobody knows where he&#8217;s been taken,&#8221; the person added. &#8220;We still don&#8217;t know why Marcus has been arrested and now we have no idea where in the US he&#8217;s been taken to and we&#8217;re extremely concerned for his welfare.&#8221;<\/span><\/p><\/blockquote>\n<p>So, they have arrested him, and are holding him incommunicado, and at this time it appears that he has not been allowed to talk to a lawyer.<\/p>\n<p>Also note that &#8220;MalWareTech&#8221; seemed to confirm that <a href=\"http:\/\/40yrs.blogspot.com\/search?q=malwaretech&amp;max-results=20&amp;by-date=true\">the WannaCry code originated with the NSA<\/a>, which might imply that there some institutional imperative to go after him that was not strictly judicial.<\/p>\n<p>Also, at the time of the Kronos release, <a href=\"https:\/\/www.theregister.co.uk\/2017\/08\/03\/wannacry_killer_hutchins_arrested\/\">Marcus Hutchins was casting about on Twitter for a copy of the code<\/a>, which seems to an awfully odd thing to do if he wrote the code in the first place:<\/p>\n<blockquote data-lang=\"en\">\n<div dir=\"ltr\" lang=\"en\">Anyone got a kronos sample?<\/div>\n<p>\u2014 MalwareTech (@MalwareTechBlog) <a href=\"https:\/\/twitter.com\/MalwareTechBlog\/status\/488373794168254464\">July 13, 2014<\/a><\/p><\/blockquote>\n<p>Marcy Wheeler also noticed an <a href=\"https:\/\/www.emptywheel.net\/2017\/08\/03\/fbi-busts-the-guy-who-saved-the-world-from-nsas-malware\/\">odd coincidence that corresponded to his arrest<\/a>: <\/p>\n<blockquote><p><span style=\"color: blue;\">In remarkably timed news, between 3:10 and 3:25 AM UTC this morning (8 PM last night Mountain Time), someone <a data-wpel-link=\"external\" href=\"https:\/\/twitter.com\/actual_ransom\" rel=\"external noopener noreferrer\">emptied out all the WannaCry accounts<\/a>.<\/span><\/p><\/blockquote>\n<p>So, while Hutchins was detained, someone took all the ransom money that&nbsp; <\/p>\n<p>This is all <b>profoundly<\/b> odd.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Marcus Hutchins, a white hat hacker who shut down the WannaCry ransomware, was just arrested by the FBI, and charged with creating and distributing a banking Trojan 3 years ago: On Wednesday, US authorities detained a researcher who goes by the handle MalwareTech, best known for stopping the spread of the WannaCry ransomware virus. In &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[],"tags":[395,435,369,367,382,421],"class_list":["post-180029","post","type-post","status-publish","format-standard","hentry","tag-computer","tag-crimes","tag-espionage","tag-internet","tag-technology","tag-weird"],"_links":{"self":[{"href":"https:\/\/www.panix.com\/~msaroff\/40years\/wp-json\/wp\/v2\/posts\/180029"}],"collection":[{"href":"https:\/\/www.panix.com\/~msaroff\/40years\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.panix.com\/~msaroff\/40years\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.panix.com\/~msaroff\/40years\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.panix.com\/~msaroff\/40years\/wp-json\/wp\/v2\/comments?post=180029"}],"version-history":[{"count":0,"href":"https:\/\/www.panix.com\/~msaroff\/40years\/wp-json\/wp\/v2\/posts\/180029\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.panix.com\/~msaroff\/40years\/wp-json\/wp\/v2\/media?parent=180029"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.panix.com\/~msaroff\/40years\/wp-json\/wp\/v2\/categories?post=180029"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.panix.com\/~msaroff\/40years\/wp-json\/wp\/v2\/tags?post=180029"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}