CASE DOSSIER sentenced

U.S. v. Marcus Hutchins (Kronos Banking Malware)

Docket: 2:17-cr-00124 Court: U.S. District Court for the Eastern District of Wisconsin Opened: 2017-07-12 Sector: Banking, Consumer Finance

Key Facts

Status
SENTENCED
Legal disposition
Loss Amount
$1.5 million
Stole banking credentials and redirected bank transactions in criminal markets.
Techniques
1
Verified mappings
Defendants
1
Named in charges
  • Legal Status: SENTENCED in U.S. District Court for the Eastern District of Wisconsin.
  • Primary Target Sector: Banking, Consumer Finance.
  • Documented Financial Loss: $1.5 million.
  • 1 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:

Case Summary

British malware researcher who previously halted the global WannaCry ransomware outbreak charged with authoring the Kronos banking trojan and UPAS kit years earlier as a teenager.
BOARDROOM EXECUTIVE BRIEF

Executive Summary for Board Members & Leadership

Plain-English Root Cause

Unauthorized intrusion originating from targeted infiltration directed against Banking, Consumer Finance networks. British malware researcher who previously halted the global WannaCry ransomware outbreak charged with authoring the Kronos banking trojan and UPAS kit years earlier as a teenager.

Operational & Financial Fallout

Stole banking credentials and redirected bank transactions in criminal markets. Impacted Banking, Consumer Finance infrastructure and associated victim operations.

3 Critical Boardroom Questions

  • 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
  • 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
  • 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Disposition: SENTENCED
Technical Threat Intelligence

Attack Anatomy & Incident Execution

Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.

Ground Zero / Infiltration Vector

Unauthorized intrusion originating from targeted infiltration directed against Banking, Consumer Finance networks. British malware researcher who previously halted the global WannaCry ransomware outbreak charged with authoring the Kronos banking trojan and UPAS kit years earlier as a teenager.

Adversary Kill Chain Flow

1 Documented Phases
1
Phase 1: Credential Access Credential Harvesting & Memory Dumping
MITRE ATT&CK T1555 →

Kronos recorded user keystrokes and used form-grabbing browser hooks to intercept unencrypted login credentials from banking websites.

Artifacts & Tooling: T1555 Credentials from Password Stores
Real-World Blast Radius & Operational Fallout

Stole banking credentials and redirected bank transactions in criminal markets. Impacted Banking, Consumer Finance infrastructure and associated victim operations.

Defensive Engineering Takeaways
Recommended Hardening Controls
✓ Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.
✓ Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.
✓ Maintain isolated, immutable backups of critical directory services and transaction databases.
✓ Deploy real-time endpoint detection and response (EDR) agents with automated containment policies.

Procedural & Incident Timeline

2017-08-02 arrest

Hutchins arrested at Las Vegas airport following the DEF CON security conference.

2019-04-19 plea

Pleads guilty to two counts of conspiracy to distribute malicious software.

2019-07-26 sentencing

Sentenced to time served and one year of supervised release with no prison time or fines, recognizing his positive contributions in halting WannaCry.

Named Defendants & Operatives

Defendant Nationality Status Prison Term Restitution Notes
Marcus Hutchins United Kingdom sentenced Pending None Security researcher who halted WannaCry; pleaded guilty to early malware development; sentenced to time served.

Substantiated MITRE ATT&CK Techniques

Technique ID Technique Name & Tactic Primary Source Evidence Excerpt Locator Verification
T1555 Credentials from Password Stores
Credential Access
"Kronos recorded user keystrokes and used form-grabbing browser hooks to intercept unencrypted login credentials from banking websites." Superseding Indictment ¶ 8, Page 4 reviewed

Cite & Embed This Case Record

Public Domain / CC0
Bluebook Legal Citation:
Cyberattack Case Library, U.S. v. Marcus Hutchins (Kronos Banking Malware), No. 2:17-cr-00124 (U.S. District Court for the Eastern District of Wisconsin 2017), https://cybercaselibrary.com/cases/us-v-hutchins-kronos-malware/
Embeddable Incident Card (HTML):
<iframe src="https://cybercaselibrary.com/embed/case/us-v-hutchins-kronos-malware" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>