{"id":8560,"date":"2017-08-03T14:11:29","date_gmt":"2017-08-03T22:11:29","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2017\/08\/03\/news-2333\/"},"modified":"2017-08-03T14:11:29","modified_gmt":"2017-08-03T22:11:29","slug":"news-2333","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2017\/08\/03\/news-2333\/","title":{"rendered":"Researcher Who Stopped WannaCry Ransomware Detained in US After Def Con"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/video-images.vice.com\/articles\/5983293f72da614c6b445c78\/lede\/1501768353139-2669961566_4bf6673c80_o.jpeg\"\/><\/p>\n<p><strong>Credit to Author: Joseph Cox| Date: Thu, 03 Aug 2017 16:22:50 +0000<\/strong><\/p>\n<p>On Wednesday, US authorities detained a researcher who goes by the handle MalwareTech, best known for stopping the spread of the WannaCry ransomware virus. <\/p>\n<p>In May, <a href=\"https:\/\/motherboard.vice.com\/en_us\/article\/4xkqqg\/a-massive-ransomware-explosion-is-hitting-targets-all-over-the-world\">WannaCry infected hospitals<\/a> in the UK, a Spanish telecommunications company, and other targets in Russia, Turkey, Germany, Vietnam, and more. Marcus Hutchins, a researcher from cybersecurity firm Kryptos Logic, inadvertently stopped WannaCry in its tracks by registering a specific website domain included in the malware&#8217;s code.<\/p>\n<p>Hutchins was arrested for <a href=\"https:\/\/motherboard.vice.com\/en_us\/article\/pagn7v\/malwaretech-wannacry-indictment-kronos-malware\">allegedly creating the Kronos banking malware<\/a>.<\/p>\n<p>Motherboard verified that a detainee called Marcus Hutchins, 23, was being held at the Henderson Detention Center in Nevada early on Thursday. A few hours after, Hutchins was moved to another facility, according to a close personal friend.<\/p>\n<p>The friend told Motherboard they &#8220;tried to visit him as soon as the detention centre opened but he had already been transferred out.&#8221; Motherboard granted the source anonymity due to privacy concerns.<\/p>\n<p>&#8220;I&#8217;ve spoken to the US Marshals again and they say they have no record of Marcus being in the system. At this point we&#8217;ve been trying to get in contact with Marcus for 18 hours and nobody knows where he&#8217;s been taken,&#8221; the person added. &#8220;We still don&#8217;t know why Marcus has been arrested and now we have no idea where in the US he&#8217;s been taken to and we&#8217;re extremely concerned for his welfare.&#8221;<\/p>\n<p class=\"article__blockquote\"><b>READ MORE:<\/b> <a href=\"https:\/\/motherboard.vice.com\/en_us\/article\/qvky75\/hackers-behind-wannacry-cashed-out-bitcoin-while-no-one-was-watching\">Hackers Behind WannaCry Cashed Out Bitcoin While No One Was Watching<\/a><\/p>\n<p>A US Marshals spokesperson told Motherboard in an email, &#8220;my colleague in Las Vegas says this was an FBI arrest. Mr. Hutchins is not in U.S. Marshals custody.&#8221;<\/p>\n<p>The FBI acknowledged a request for comment but did not provide one in time for publication.<\/p>\n<p>Shortly before his arrest, Hutchins was in Las Vegas during Black Hat and Def Con, two annual hacking conferences.<\/p>\n<p>&#8220;We are aware a UK national has been arrested but it&#8217;s a matter for the authorities in the US,&#8221; a spokesperson for the UK&#8217;s National Crime Agency told Motherboard in an email.<\/p>\n<p>A spokesperson from the UK&#8217;s National Cyber Security Centre told Motherboard in an email, &#8220;We are aware of the situation. This is a law enforcement matter and it would be inappropriate to comment further.&#8221;<\/p>\n<p>A UK Foreign Office spokesperson told Motherboard in an email, &#8220;We are in contact with the local authorities in Las Vegas following the arrest of a British man, and are providing support to his family.&#8221;<\/p>\n<p class=\"article__blockquote\"><b><i>Got a tip? You can contact this reporter securely on Signal at +44 20 8133 5190, OTR chat at jfcox@jabber.ccc.de, or email joseph.cox@vice.com<\/i><\/b><\/p>\n<p><b> <i> Get six of our favorite Motherboard stories every day <\/i><\/b><a href=\"http:\/\/motherboard.club\/\" target=\"_blank\"><b> <i> by signing up for our newsletter.<\/i><\/b><\/a><\/p>\n<p><a href=\"https:\/\/motherboard.vice.com\/en_us\/article\/ywp8k5\/researcher-who-stopped-wannacry-ransomware-detained-in-us-after-def-con\" target=\"bwo\" >https:\/\/motherboard.vice.com\/en_us\/rss<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/video-images.vice.com\/articles\/5983293f72da614c6b445c78\/lede\/1501768353139-2669961566_4bf6673c80_o.jpeg\"\/><\/p>\n<p><strong>Credit to Author: Joseph Cox| Date: Thu, 03 Aug 2017 16:22:50 +0000<\/strong><\/p>\n<p>Marcus Hutchins, AKA MalwareTech, previously registered a specific domain included in the ransomware\u2019s code, which stopped the malware from spreading.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10643,10378],"tags":[885,13312,3919,3764,854,714],"class_list":["post-8560","post","type-post","status-publish","format-standard","hentry","category-independent","category-security","tag-arrest","tag-def-con","tag-hacking","tag-malware","tag-police","tag-security"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/8560","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=8560"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/8560\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=8560"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=8560"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=8560"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}