Profile and behind-the-scenes story of Marcus “MalwareTech” Hutchins, who helped stop the WannaCry attack and pled guilty to selling the Kronos banking malware
At 22, he single-handedly put a stop to the worst cyberattack the world had ever seen. Then he was arrested by the FBI. Tweets: @malwaretechblog , @a_greenberg , @dakacki , @issielapowsky , @wired , @iancoldwater , @malwaretechblog , @malwaretechblog , and @malwaretechblog Tweets: @malwaretechblog : Ok, here we go. https://www.wired.com/... Andy Greenberg / @a_greenberg : Three years ago today, Marcus Hutchins stopped WannaCry, an $8 billion cyberattack. Then the FBI arrested him. Today we're publishing a 14,000-word cover story that finally tells his full, untold tale, from 15yo criminal to hero to convict to redemption. https://www.wired.com/... @dakacki : Few thoughts/feelings here: 1. This article is worth every second of your time. @a_greenberg absolutely killed this. 2. I remember how much a dick that Dave Aitel guy was. 3. Renewed Fed rage. 4. Judge Stadtmueller gives me a glimmer of hope in the judicial system. Go read https://twitter.com/... Issie Lapowsky / @issielapowsky : This is clearly a must-read. @a_greenberg is the only person I would want to tell me this story, and man does he tell this story! https://twitter.com/... @wired : At 22, Marcus Hutchins single-handedly saved the internet. From a bedroom in his parents' house, Hutchins stopped WannaCry, a self-spreading digital worm that, at the time, was the worst cyberattack the world had ever seen 1/ https://www.wired.com/... Ian Coldwater / @iancoldwater : People are complicated. Sometimes those who have done bad can also do incredible amounts of good. I was a loud and proud @MalwareTechBlog supporter and I have no regrets at all. 💙 https://twitter.com/... @malwaretechblog : This is something I've wanted to do for a long time. I felt it better to share the full unadulterated story, and let people make up their own minds. It meant discussing a lot of uncomfortable facts about my past, but I want the story not to be some airbrushed half-truth. @malwaretechblog : The article doesn't make it very clear, but the 1st deal I was offered was a cooperation deal for no jail time, which i declined. The second (worse) deal was a pure plea (i admit that everything the DOJ said about me is true, but I don't cooperate with LE), That's the one i took. https://twitter.com/... @malwaretechblog : In 3 hours it'll be the 3rd year anniversary of WannaCry. It'll also be the 1st year that I'm free to talk about certain things.
Context & Ripple Effects
Three years after he was arrested by the FBI at Def Con for allegedly helping spread the Kronos banking trojan, Wired is publishing Andy Greenberg's 14,000-word account of Marcus Hutchins' full arc — teenage malware author, then the researcher credited with single-handedly stopping WannaCry, an $8 billion attack. The story lands a year after Hutchins pled guilty to conspiring to distribute Kronos and was sentenced to time served plus one year of supervised release, closing a legal saga that had hung over him since 2017.
What makes the piece matter now is what it settles: an earlier 2018 profile covered only the pending-trial version of events, and Hutchins reportedly declined a cooperation deal that would have spared him jail. With the case resolved, the full record of both halves of his career — the Kronos years and the kill switch — is finally on the table in one place.
First-order effects
- Hutchins exits supervised release into a rehabilitated public standing: the definitive long-form account reframes him from federal defendant back to the researcher who stopped WannaCry, with the guilty plea acknowledged rather than litigated.
Second-order effects
- The case hardens into a reference point for prosecutors weighing researchers with dual histories — the time-served outcome shows the DoJ will close such cases without maximum penalties even when a cooperation deal is refused.
Third-order effects
- If this pattern holds, the security industry's reliance on reformed black-hat talent gets a durable legal template: past malware authorship is prosecutable but not necessarily career-ending, formalizing the gray zone between underground coder and white-hat defender.
The trend: Security research is institutionalizing the redemption arc, where former malware authors can become celebrated defenders so long as they accept legal accountability for their past.