{"id":8564,"date":"2017-08-03T14:11:39","date_gmt":"2017-08-03T22:11:39","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2017\/08\/03\/news-2337\/"},"modified":"2017-08-03T14:11:39","modified_gmt":"2017-08-03T22:11:39","slug":"news-2337","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2017\/08\/03\/news-2337\/","title":{"rendered":"WannaCry Researcher Indicted for Allegedly Creating Banking Malware"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/video-images.vice.com\/articles\/598372d93889ba4c718755d9\/lede\/1501787259824-GettyImages-619466056.jpeg\"\/><\/p>\n<p><strong>Credit to Author: Joseph Cox| Date: Thu, 03 Aug 2017 19:07:54 +0000<\/strong><\/p>\n<p>On Thursday, <a href=\"https:\/\/motherboard.vice.com\/en_us\/article\/ywp8k5\/researcher-who-stopped-wannacry-ransomware-detained-in-us-after-def-con\">Motherboard reported<\/a> that Marcus Hutchins, a security researcher known for helping to stop the spread of the WannaCry ransomware, was arrested in Las Vegas. <\/p>\n<p>Now, US prosecutors claim the researcher helped create and distribute the Kronos banking trojan between July 2014 and July 2015.<\/p>\n<p>&#8220;Defendant MARCUS HUTCHINS created the Kronos malware,&#8221; <a href=\"https:\/\/www.documentcloud.org\/documents\/3912524-Kronos-Indictment-R.html\" target=\"_blank\">the indictment, embedded below, claims<\/a>.<\/p>\n<p>The indictment includes information on, but does not name, a second defendant. The conspiracy allegedly included advertising Kronos on internet forums and selling the malware itself. <\/p>\n<p>The indictment includes a list of specific instances where the second defendant allegedly sold and advertised the Kronos malware, including on the <a href=\"https:\/\/motherboard.vice.com\/en_us\/article\/evd7xw\/us-europol-and-netherlands-announce-shutdowns-of-two-massive-dark-web-markets\">recently defunct AlphaBay<\/a> dark web marketplace.<\/p>\n<p class=\"article__blockquote\"> <b> <i>Got a tip? You can contact this reporter securely on Signal at +44 20 8133 5190, OTR chat at jfcox@jabber.ccc.de, or email joseph.cox@vice.com<\/i> <\/b> <\/p>\n<p>The indictment claims an &#8220;overt act&#8221; taken by the suspects was the use of a video explaining how Kronos works. This video was posted on YouTube on July 13, 2014, the date listed in the indictment (the video has since been removed from YouTube.)<\/p>\n<p>The malware was designed to steal banking credentials, by directing targets to fake, malicious banking websites. <a href=\"https:\/\/threatpost.com\/new-kronos-banking-malware-advertised-on-russian-forums\/107210\/\" target=\"_blank\">According to <i> Threat Post<\/i><\/a>, Kronos was advertised on forums for $7,000.<\/p>\n<p>&#8220;You need just a domain or a payment including the domain fee. You&#8217;ll have full access to the C&#038;C, without any limits or restrictions during test mode,&#8221; a <a href=\"https:\/\/securityintelligence.com\/the-father-of-zeus-kronos-malware-discovered\/\" target=\"_blank\">translated version of a Russian language post<\/a> advertising the malware reads.<\/p>\n<div data-iframely-id=\"EEa4eYa\" class=\"article__embed article__embed--iframely\">\n<div style=\"left: 0; width: 100%; height: 0; position: relative; padding-bottom: 141.4227%;\" data-iframely-smart-iframe=\"true\"><iframe  src= width=\"100%\" height=\"420\" frameborder=\"0\" ><\/iframe> <\/div>\n<\/div>\n<p><b><i>Get six of our favorite Motherboard stories every day <a href=\"http:\/\/motherboard.club\/\" target=\"_blank\">by signing up for our newsletter<\/a>.<\/i><\/b><\/p>\n<p><a href=\"https:\/\/motherboard.vice.com\/en_us\/article\/pagn7v\/malwaretech-wannacry-indictment-kronos-malware\" target=\"bwo\" >https:\/\/motherboard.vice.com\/en_us\/rss<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/video-images.vice.com\/articles\/598372d93889ba4c718755d9\/lede\/1501787259824-GettyImages-619466056.jpeg\"\/><\/p>\n<p><strong>Credit to Author: Joseph Cox| Date: Thu, 03 Aug 2017 19:07:54 +0000<\/strong><\/p>\n<p>On Wednesday, US authorities detained Marcus Hutchins, aka MalwareTech, for his alleged role in creating and distributing the Kronos banking trojan.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10643,10378],"tags":[13326,12252],"class_list":["post-8564","post","type-post","status-publish","format-standard","hentry","category-independent","category-security","tag-malwaretech","tag-wannacry"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/8564","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=8564"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/8564\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=8564"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=8564"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=8564"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}