Skip to main content
Darknet Diaries

158: MalwareTech

66 min episode · 2 min read

Episode

66 min

Read time

2 min

Topics

Career Growth, Marketing, Science & Discovery

AI-Generated Summary

Key Takeaways

  • Kill Switch Discovery: WannaCry contained an unregistered domain that functioned as a kill switch. Registering the domain immediately stopped the ransomware's spread globally, though Hutchins didn't realize he'd stopped it until hours later when media reported the attack had ended.
  • Federal Charging Strategy: US prosecutors don't charge malware creation directly since it's not illegal. Instead, they use obscure laws like wiretapping statutes, arguing keystroke logging equals phone line interception, allowing conspiracy charges even without direct hacking involvement by the defendant.
  • Bail System Exploitation: Federal cases can trap foreign nationals for years. Hutchins couldn't leave the US due to bail conditions, couldn't work due to expired tourist visa, yet couldn't return home. The prosecution uses this prolonged stress as leverage to force plea deals.
  • Time Served Sentencing: Judges can sentence defendants to time already spent fighting the case rather than additional prison time. Hutchins received this outcome after two years of legal battle, with the judge citing his WannaCry heroics and self-rehabilitation as justification for no jail.
  • Anonymity Protection Failure: Using proxy domain registration and anonymous social media accounts isn't sufficient protection. Journalists traced Hutchins through his Twitter activity patterns and published his real name, address, and photos within three days, ending his anonymous researcher career permanently.

What It Covers

Marcus Hutchins, known as MalwareTech, stopped the WannaCry ransomware attack in 2017 by accidentally activating a kill switch, then faced FBI arrest for creating Kronos banking malware years earlier as a teenager.

Key Questions Answered

  • Kill Switch Discovery: WannaCry contained an unregistered domain that functioned as a kill switch. Registering the domain immediately stopped the ransomware's spread globally, though Hutchins didn't realize he'd stopped it until hours later when media reported the attack had ended.
  • Federal Charging Strategy: US prosecutors don't charge malware creation directly since it's not illegal. Instead, they use obscure laws like wiretapping statutes, arguing keystroke logging equals phone line interception, allowing conspiracy charges even without direct hacking involvement by the defendant.
  • Bail System Exploitation: Federal cases can trap foreign nationals for years. Hutchins couldn't leave the US due to bail conditions, couldn't work due to expired tourist visa, yet couldn't return home. The prosecution uses this prolonged stress as leverage to force plea deals.
  • Time Served Sentencing: Judges can sentence defendants to time already spent fighting the case rather than additional prison time. Hutchins received this outcome after two years of legal battle, with the judge citing his WannaCry heroics and self-rehabilitation as justification for no jail.
  • Anonymity Protection Failure: Using proxy domain registration and anonymous social media accounts isn't sufficient protection. Journalists traced Hutchins through his Twitter activity patterns and published his real name, address, and photos within three days, ending his anonymous researcher career permanently.

Notable Moment

After stopping the world's largest ransomware attack from his parents' basement in Devon, Hutchins was arrested by FBI agents disguised as customs officers at Las Vegas airport. They handed him printed compiled code from Kronos malware he'd written as a teenager.

Know someone who'd find this useful?

Episode Transcript

Oh my gosh. Oh my gosh. Oh my gosh. I'm squealing over here. After years and years of trying to get today's guest on the show, he finally said yes. I'm so excited for this one. I've been sliding into his DMs for years. Hey. Can I interview you? And I swear he always has the same answer every time. He's like, who are you? And I say something like, oh, I'm a podcaster, and I I really wanna hear your story. And he's like, no. Thank you. And fair answer, I wouldn't wanna talk to me either if I was in his position. And then I saw him at a party at Defcon, and when I when I first approached him in person, he was hiding behind a sign, trying not to be seen. So I I stand out in a crowd, so I've learned that, like, signs are my best friend. We can hide behind the lamppost. We can hide behind the tree. We can hide behind the sign. But if I stand in the middle of the room, like, it's gonna draw a lot more attention than, than I necessarily maybe want. Although, I've got to the point now where I I I think I can just handle it. But I I do remember our first interactions. I think part of the awkwardness was I'm very bad at recognizing faces, and you were wearing a mask the first time you saw me. It's true. I had a disguise on, and, yeah, I asked to interview him, and he had no idea who I was. He's just like, who are you? In my defense, there is no photos of you online, and I have checked. So It's true. There is there is no way I could have known. It's true. I tried real hard not to have any photos of me on the Internet. I'm a very private person. But I swear, every time I asked him for an interview, he just kept asking me the same thing. Who are you? No, thank you. So I remember we had, like, quite a long conversation, and then you went away, and you came back without the mask. And then you came back, and you sort of went to reengage the conversation, and I had no idea who you were. I was like, who is this random guy? Okay. Fair point. I wear a lot of disguises, so you're right. Some of this is on me. But I'm happy to announce that today, finally, I am interviewing MalwareTech. I'm MalwareTech, and I'm an anonymous security researcher. These are true stories from the dark side of the Internet. I'm Jack Rhysider. This is Darknet Diaries. This episode is sponsored by DeleteMe. DeleteMe makes it easy, quick, and safe to remove your personal data online at a time when surveillance and data breaches are common enough to make everyone vulnerable. DeleteMe does all the hard work of wiping you and your family's …

Get the full transcript (12,446 words) + summary by email — free

One-time email with the complete transcript and AI summary of this episode. No account needed.

One email, no spam. We’ll also show you what SignalCast does.

Browse all Darknet Diaries transcripts →

You just read a 3-minute summary of a 63-minute episode.

Get Darknet Diaries summarized like this every Monday — plus up to 2 more podcasts, free.

Pick Your Podcasts — Free

Keep Reading

More from Darknet Diaries

We summarize every new episode. Want them in your inbox?

Similar Episodes

Related episodes from other podcasts

Explore Related Topics

This podcast is featured in Best Tech Podcasts (2026) — ranked and reviewed with AI summaries.

You're clearly into Darknet Diaries.

Every Monday, we deliver AI summaries of the latest episodes from Darknet Diaries and 192+ other podcasts. Free for one show.

Start My Monday Digest

No credit card · Unsubscribe anytime