Marcus Hutchins: From WannaCry Kill Switch to Expel

Marcus Hutchins registered the domain that halted the 2017 WannaCry worm, later pleaded guilty to earlier hacking charges, received probation and now works as Principal Threat Researcher at Expel.

Marcus Hutchins, a British-born researcher who was working in Los Angeles in 2017, registered the web address embedded in the WannaCry ransomware’s code that acted as a kill switch and halted the worm’s automatic spread. He bought the domain for $10.69 and configured it to return a standard web response. When the malware queried that address and received a 200 status reply, it stopped propagating.

The WannaCry outbreak used a leaked U.S. government exploit known as EternalBlue to scan for exposed SMB ports and install a backdoor called DoublePulsar. Attackers then deployed a ransomware payload that replicated across networks. The payload’s encryption worked in many cases while its decryption routine failed, leaving affected systems unusable. The inclusion of the unregistered domain in the malware and why its presence disabled the worm remain unexplained by the code’s authors.

Hutchins had begun publishing technical analysis under the MalwareTech name in 2013 and taught himself multiple programming languages after receiving his first PC at age 13. Early in his online activity he sold tools and proof-of-concept code in forums where both security researchers and criminals were active. He later described a period of moral ambiguity and said he stopped working with groups that used his code for harmful purposes.

By 2016 he had taken a research-and-development role at a Los Angeles firm. In May 2017, while analyzing the WannaCry samples, he found the unregistered domain and registered it to monitor traffic and limit further automatic infections. The site received tens of thousands of queries every few minutes as researchers and defenders observed the outbreak.

Three months after registering the domain, Hutchins was arrested by the FBI on charges related to his earlier online activities. He was detained at the Nevada Southern Detention Center and released after $30,000 cash bail was posted by cybersecurity professional Tarah M. Wheeler. Hutchins spent several years defending the case in U.S. courts and ultimately pleaded guilty to computer hacking and to advertising a wiretapping device. A judge sentenced him to one year of probation and cited his subsequent work in the field.

Hutchins, now in his early 30s, works as Principal Threat Researcher at cybersecurity firm Expel. He focuses on malware analysis and threat intelligence and continues to publish research under the MalwareTech moniker. He has described his motivation as a desire to understand how systems work, saying, “Not knowing more about how something works bothers me.”

Articles by this author