{
  "id": "case-marcus-hutchins-kronos",
  "slug": "us-v-hutchins-kronos-malware",
  "title": "U.S. v. Marcus Hutchins (Kronos Banking Malware)",
  "summary": "British malware researcher who previously halted the global WannaCry ransomware outbreak charged with authoring the Kronos banking trojan and UPAS kit years earlier as a teenager.",
  "case_number": "2:17-cr-00124",
  "court": "U.S. District Court for the Eastern District of Wisconsin",
  "district": "E.D. Wis.",
  "country": "United States",
  "opened_at": "2017-07-12",
  "status": "sentenced",
  "victim_sector": "Banking, Consumer Finance",
  "victim_country": "United States, Germany, United Kingdom",
  "loss_amount_usd": 1500000,
  "loss_amount_note": "Stole banking credentials and redirected bank transactions in criminal markets.",
  "first_seen_at": "2014-06-01T00:00:00Z",
  "last_updated_at": "2026-08-25T11:00:00Z",
  "actor_slug": "malwaretech",
  "defendant_slugs": [
    "marcus-hutchins"
  ],
  "cves": [],
  "techniques": [
    {
      "technique_id": "T1555",
      "evidence_excerpt": "Kronos recorded user keystrokes and used form-grabbing browser hooks to intercept unencrypted login credentials from banking websites.",
      "evidence_locator": "Superseding Indictment \u00b6 8, Page 4",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Indictment: U.S. v. Hutchins",
      "source_url": "https://www.justice.gov/usao-edwi/pr/british-national-pleads-guilty-developing-and-distributing-malicious-computer-code",
      "technique_name": "Credentials from Password Stores",
      "tactic": "Credential Access"
    }
  ],
  "events": [
    {
      "event_type": "arrest",
      "event_date": "2017-08-02",
      "description": "Hutchins arrested at Las Vegas airport following the DEF CON security conference."
    },
    {
      "event_type": "plea",
      "event_date": "2019-04-19",
      "description": "Pleads guilty to two counts of conspiracy to distribute malicious software."
    },
    {
      "event_type": "sentencing",
      "event_date": "2019-07-26",
      "description": "Sentenced to time served and one year of supervised release with no prison time or fines, recognizing his positive contributions in halting WannaCry."
    }
  ],
  "attack_anatomy": {
    "ground_zero": "Unauthorized intrusion originating from targeted infiltration directed against Banking, Consumer Finance networks. British malware researcher who previously halted the global WannaCry ransomware outbreak charged with authoring the Kronos banking trojan and UPAS kit years earlier as a teenager.",
    "blast_radius": "Stole banking credentials and redirected bank transactions in criminal markets. Impacted Banking, Consumer Finance infrastructure and associated victim operations.",
    "kill_chain": [
      {
        "phase": "Phase 1: Credential Access",
        "title": "Credential Harvesting & Memory Dumping",
        "description": "Kronos recorded user keystrokes and used form-grabbing browser hooks to intercept unencrypted login credentials from banking websites.",
        "technical_artifacts": [
          "T1555",
          "Credentials from Password Stores"
        ],
        "mitre_technique_id": "T1555"
      }
    ],
    "defensive_takeaways": [
      "Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.",
      "Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.",
      "Maintain isolated, immutable backups of critical directory services and transaction databases.",
      "Deploy real-time endpoint detection and response (EDR) agents with automated containment policies."
    ]
  }
}