iTnews
  • Home
  • News
  • Technology
  • Security

WannaCry hero arrested over banking malware

By Juha Saarinen on Aug 4, 2017 6:45AM
WannaCry hero arrested over banking malware

Hutchins accused of writing Kronos banker.

Marcus Hutchins, the security researcher credited for blunting the effect of the WannaCry ransomware attack in May this year, has been arrested in the United States.

Briton Hutchins - who goes under the name Malwaretech - and an unnamed individual were arrested in Las Vegas ahead of this week's Black Hat and DefCon security conferences.

A US grand jury indictment published by Motherboard states the pair face six charges related to creating, distributing and demonstrating the Kronos malware in 2014.

Hutchins is said to have written Kronos, while the unnamed defendant sold the malware on the Alphabay dark web market and Russian internet forums for an asking price of US$2000 to US$3000.

Kronos is a credentials-stealing malware that attempts to exfiltrate victims' bank account details to the attackers that control it.

The unnamed defendant is said to have demonstrated Kronos in a YouTube video as part of his marketing effort for the malware. It was available until recently but has now been taken down by YouTube.

Another YouTube video purporting to show how to set up Kronos for a banking botnet remains available.

Hutchins rose to fame in May after he registered a domain that deactivated dissemination of WannaCry.

He was widely lauded for his quick thinking, and received a US$13,000 bug bounty for his efforts.

WannaCry ransom money on the move

Separately, the ransom collected by the WannaCry attackers has been moved out of the Bitcoin digital wallets it was being stored in.

The Actual Ransom twitter bot tweeted that three wallets had been emptied of a total of US$140,000 (A$176,200) in Bitcoin.

It's not clear at this stage what the final destination for the WannaCry ransom is, or who it is trying to cash out the payments.

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
kronosmalwaremarcus hutchinssecuritywannacrywannacrypt

Partner Content

Why rethinking your CMS is crucial for customer retention
Promoted Content Why rethinking your CMS is crucial for customer retention
Security "mindset shift" needed to protect organisations
Promoted Content Security "mindset shift" needed to protect organisations
Security: Understanding the fundamentals of governance, risk & compliance
Promoted Content Security: Understanding the fundamentals of governance, risk & compliance
The Great Resignation has intensified insider security threats
Promoted Content The Great Resignation has intensified insider security threats

Sponsored Whitepapers

Free eBook: Digital Transformation 101 – for banks
Free eBook: Digital Transformation 101 – for banks
Why financial services need to tackle their Middle Office
Why financial services need to tackle their Middle Office
Learn: The latest way to transfer files between customers
Learn: The latest way to transfer files between customers
Extracting the value of data using Unified Observability
Extracting the value of data using Unified Observability
Planning before the breach: You can’t protect what you can’t see
Planning before the breach: You can’t protect what you can’t see

Events

  • Forrester Technology & Innovation Asia Pacific 2022
By Juha Saarinen
Aug 4 2017
6:45AM
0 Comments

Related Articles

  • VMware, F5, Log4j added to EnemyBot attack targets
  • Google adds phishing protection to Workspace apps
  • FBI Cyclops Blink operation disinfected thousands of WatchGuard appliances
  • Misconfigured VPN behind destructive Viasat attack
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Aussie Broadband nears end of NBN PoI fibre rollout

Aussie Broadband nears end of NBN PoI fibre rollout

Telstra deregisters 900MHz sites “hindering” Optus 5G rollout

Telstra deregisters 900MHz sites “hindering” Optus 5G rollout

Student details, photos exposed in University of WA data breach

Student details, photos exposed in University of WA data breach

Transport for NSW exits Global Switch data centre

Transport for NSW exits Global Switch data centre

Digital Nation

Personalisation strategies need to be built from the ground up
Personalisation strategies need to be built from the ground up
Case Study: Multicloud business drivers at MLC Life Insurance
Case Study: Multicloud business drivers at MLC Life Insurance
COVER STORY: Multiple cloud models make security more complex
COVER STORY: Multiple cloud models make security more complex
COVER STORY: What happens when Google changes its algorithm?
COVER STORY: What happens when Google changes its algorithm?
Case Study: Swinburne University overhauls student management system
Case Study: Swinburne University overhauls student management system
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.