Breaking
SecurityDeveloping Story

Gray to White: A Hacker's Redemption Arc

Marcus Hutchins, who halted WannaCry, recounts his path from malware author to security researcher.

··1 hour ago·6 min read
turned on gray laptop computer
Photo by Luca Bravo on Unsplash

Marcus Hutchins does not consider himself a hacker, but he accepts the term because it describes what he once did. Born in Ascot, England, he was a 22-year-old cyber threat analyst in 2017 when he inadvertently became a global hero by finding a kill switch for WannaCry, a virulent cryptoworm that crippled hundreds of thousands of systems. Months later, the FBI arrested him for crimes he committed before his moment of fame, launching a legal battle that would define his path from the gray zone of cybercrime to redemption.

The Curious Mind

Hutchins's journey into the digital underground began with an insatiable curiosity. Unlike many hackers who seek to alter systems, Hutchins only wanted to understand them. "Not knowing more about how something works bothers me," he explains. This drive often spiraled: from electronics to quantum physics, he would dive endlessly into the mechanics of any system that caught his attention.

His neurodiversity, a common trait among natural hackers, fueled this intensity. "If I get interested enough in a task, I find it very easy to just commit a lot of time to that task. So of course, the flip side of that is, if I’m not interested in said task, I am basically useless." This polarization led to deep expertise in coding, but neglect of other school subjects. Given his first computer at 13, he taught himself VB, PHP, C, C++, and Assembly within a few years, but at the cost of his academic qualifications.

"I was just this very young kid with too many skills in a certain area and no productive outlet for them. Academic qualifications were already out of the window. I was basically just a writer of code."

From Code to Crime

Like-minded peers gravitated toward him. "I started getting involved on cybercrime forums quite early on. My skill was primarily coding, so I ended up writing hacks rather than doing hacking." He never personally engaged in hacking; instead, he became a professional malware developer for a cybercrime group, maintaining back doors and code designed to subvert antiviruses and bypass security systems. This began while he was still in school, where he would briefly shut down school computers for fun.

In 2013, he launched an anonymous blog called MalwareTech, focusing on how malware works and including proof-of-concepts. The blog attracted both cybersecurity professionals and cybercriminals, and the latter were willing to pay for his work. Hutchins didn't stop them. "There was never a distinct line where I could think, ‘This is OK, but that isn’t’. Things aren’t black and white – it’s all just a big scale of gray," he comments.

He distanced himself from the consequences of his code. "From my perspective, I’m writing some code, which I then sell to a person, and then I don’t see it again after that. That’s just kind of the way that scene works." He compared it to selling a kitchen knife, unsure whether it would cut vegetables or a person. But the distancing didn't last.

The Turn to Legitimacy

Over time, Hutchins grew close to some organizations using his code and witnessed the harm it caused. "I just didn’t like knowing that I was responsible for those kinds of things. I decided to cut ties and look for a legitimate job." This marked a conscious choice between morality and immorality, a decision many young hackers face. For Hutchins, it stemmed from an innate understanding of good and bad that matured with age.

MalwareTech had also introduced him to cybersecurity professionals. In 2016, he became a research and development lead for a Los Angeles firm and moved to the US, a year before WannaCry. He was now a legitimate professional.

The Kill Switch Discovery

WannaCry was a massive outbreak, affecting more than 200,000 computers in around 150 countries within days. "WannaCry was a big deal at the time. Unrelated organizations were going down all round the country, and nobody really knew why. That sort of interested me, because it was nothing like anything I had seen before."

The worm used the leaked NSA exploit EternalBlue, which scanned the internet for computers with an open SMB port and installed the DoublePulsar backdoor. The ransomware then copied itself automatically from machine to machine. The encryption worked, but the decryption failed, turning it into a destructive wiper.

While analyzing the malware, Hutchins noticed an unregistered domain in the code. Researchers often register such domains to monitor malware, so he did too, paying $10.69 for iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com. The domain was immediately flooded with tens of thousands of queries every couple of minutes. "So, I’m looking for a way to understand what it’s doing and stop it, when I learn that WannaCry itself had stopped. The domain was the kill switch simply by being on the internet and responding to the queries with a 200 status code."

The exact reason why the malware behaved this way remains unclear, but the effect was simple: "It basically deactivates the thing. So, all we need do is maintain a web server with the web address pointed to that web server, and as long as that server does not go down, the malware is not able to spread."

Arrest and Trial

Three months after his heroic act, the FBI arrested Hutchins. "It was basically for the stuff I had been doing earlier. They didn’t find out about it until long after the fact, but for whatever reason, they decided they still wanted to prosecute me. I ended up getting sent through the US court system for something that I had previously done and had since stopped doing. I spent the next three years after WannaCry fighting this case in court related to conduct that occurred long before stopping WannaCry."

Held in the Nevada Southern Detention Center, he was released after one week when Tarah M. Wheeler, a cybersecurity leader and activist, posted $30,000 cash bail. The case lasted two years, ending with Hutchins pleading guilty to computer hacking and advertising a wiretapping device, among other charges. The judge, recognizing his rehabilitation and perhaps the WannaCry incident, sentenced him to one year of probation.

Redemption and Reflection

Hutchins's story is an uncommon arc from passive wrongdoer to active good guy. His early work on MalwareTech led to prosecution, but also raised his profile as a malware expert. The publicity from WannaCry likely helped the FBI connect his name to the anonymous blog, leading to charges. "No bad deed goes unpunished," he reflects, and "no good deed goes unpunished" also proved true.

He continues to publish MalwareTech, now his pseudonym, but the content has shifted to legitimate cybersecurity. Last year, he was headhunted and is now, at 32, Principal Threat Researcher at Expel, where he focuses on threat intelligence and malware analysis—essentially the same work, but fully legal.

Why It Matters

Hutchins's journey highlights the complex paths that lead people into cybercrime and back. It underscores the importance of providing productive outlets for young, technically skilled individuals who might otherwise drift into the gray zone. His story also raises questions about how the justice system treats those who turn their skills to defense. For the cybersecurity industry, it's a reminder that today's threat actors could become tomorrow's defenders, and that redemption is possible when talent is channeled constructively. For businesses and consumers, it's a lesson in the value of researchers who can stop attacks—and the need to support them, not just when they save the day, but when they seek to make amends.

#marcus-hutchins#wannacry#hacker-interview#cybercrime#malware

Sources

Iliyas

Editor, Xploitwire

This article was researched and drafted through our automated editorial pipeline from the sources listed above, then checked against those sources through our automated fact-check process, under the editorial policies set by Iliyas. Our Automation Policy →

← Back to all stories