U.S. v. Marcus Hutchins (Kronos Banking Malware)
Key Facts
- Legal Status: SENTENCED in U.S. District Court for the Eastern District of Wisconsin.
- Primary Target Sector: Banking, Consumer Finance.
- Documented Financial Loss: $1.5 million.
- 1 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Case Summary
Executive Summary for Board Members & Leadership
Plain-English Root Cause
Unauthorized intrusion originating from targeted infiltration directed against Banking, Consumer Finance networks. British malware researcher who previously halted the global WannaCry ransomware outbreak charged with authoring the Kronos banking trojan and UPAS kit years earlier as a teenager.
Operational & Financial Fallout
Stole banking credentials and redirected bank transactions in criminal markets. Impacted Banking, Consumer Finance infrastructure and associated victim operations.
3 Critical Boardroom Questions
- 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
- 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
- 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Attack Anatomy & Incident Execution
Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.
Unauthorized intrusion originating from targeted infiltration directed against Banking, Consumer Finance networks. British malware researcher who previously halted the global WannaCry ransomware outbreak charged with authoring the Kronos banking trojan and UPAS kit years earlier as a teenager.
Adversary Kill Chain Flow
1 Documented PhasesKronos recorded user keystrokes and used form-grabbing browser hooks to intercept unencrypted login credentials from banking websites.
Stole banking credentials and redirected bank transactions in criminal markets. Impacted Banking, Consumer Finance infrastructure and associated victim operations.
Procedural & Incident Timeline
Hutchins arrested at Las Vegas airport following the DEF CON security conference.
Pleads guilty to two counts of conspiracy to distribute malicious software.
Sentenced to time served and one year of supervised release with no prison time or fines, recognizing his positive contributions in halting WannaCry.
Named Defendants & Operatives
| Defendant | Nationality | Status | Prison Term | Restitution | Notes |
|---|---|---|---|---|---|
| Marcus Hutchins | United Kingdom | sentenced | Pending | None | Security researcher who halted WannaCry; pleaded guilty to early malware development; sentenced to time served. |
Substantiated MITRE ATT&CK Techniques
| Technique ID | Technique Name & Tactic | Primary Source Evidence Excerpt | Locator | Verification |
|---|---|---|---|---|
| T1555 | Credentials from Password Stores Credential Access | "Kronos recorded user keystrokes and used form-grabbing browser hooks to intercept unencrypted login credentials from banking websites." | Superseding Indictment ¶ 8, Page 4 | reviewed |