MalwareTech, the security researcher who stopped the WannaCry ransomware, has been arrested in Las Vegas on charges related to the creation of the Kronos banking trojan along with another individual.
The arrest – first reported by Motherboard – took place on August 2, after the DEF CON security conference.
According to the official announcement, authorities arrested MalwareTech (his real name is Marcus Hutchins, 23 years old from the United Kingdom) for creating and updating Kronos, a known banking trojan that uses a technique called web injects to insert fake login pages to online banking portals in different browsers.
Kronos first appeared in July 2014 and was last seen actively in June 2016. In July 2014, Kronos was available for sale on a large Russian underground forum with a price tag of up to $7,000.
The official indictment accuses MalwareTech of creating and updating the Kronos trojan, while his accomplice – anonymous to this day – posted the malware on a hacking forum (for $3,000) and on AlphaBay (for $2,000).
US officials seized the servers of the AlphaBay Dark Web marketplace on July 4, 2017.The indictment was filed on July 11, 2017.
According to the indictment, the two partners made at least one successful sale of Kronos on AlphaBay, again revealing that US authorities likely used seized data from AlphaBay to verify and confirm the purchase.
In May 2017, MalwareTech became world-famous when it stopped the spread of the WannaCry ransomware.
MalwareTech's arrest has surprised the security community, with his fellow security researchers finding the allegations hard to believe. Many believe that MalwareTech was framed or that the researchers may have made errors in their investigation. [1, 2, 3, 4].
At the time of his arrest, MalwareTech was an employee of the encryption company Kryptos Logic.
