[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fqk5CBdWstWCUMb7Mb26rjLieHefhHuc4CQMjEbrxmBg":3},{"article":4,"iocs":42},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":24,"category":25,"article_tags":29},"84969642-ee9c-4a59-ba2f-9253cd0c739a","Hacker Conversations: Marcus Hutchins and the Journey From the Gray Zone to Redemption","hacker-conversations-marcus-hutchins-and-the-journey-from-the-gray-zone-to-redem-dd627a","Marcus Hutchins doesn’t personally consider himself a hacker – but he accepts the epithet because it’s a widely used term for what he once did. The post Hacker Conversations: Marcus Hutchins and the Journey From the Gray Zone to Redemption appeared first on SecurityWeek.","Marcus Hutchins, known for discovering the WannaCry kill switch, reflects on his past involvement with cybercrime forums and developing malware. He explains his motivation stemmed from an intense desire to understand systems, leading him to write code for hackers rather than engage in hacking himself. Despite his role in stopping WannaCry, he was arrested by the FBI, highlighting the complex world of individuals operating in the 'gray zone' of cybersecurity.","Marcus Hutchins, WannaCry hero, discusses his journey from cybercrime forums to cybersecurity.","Marcus Hutchins doesn’t personally consider himself a hacker – but he accepts the epithet because it’s a widely used term for what he once did. Born in Ascot, England, he was working as a cyber threat analyst for an LA-based cybersecurity company in 2017 (aged 22), when he became the world’s hero for finding a kill switch for the particularly virulent and destructive cryptoworm (ransomware spread by a worm) known as WannaCry. The ransomware decryption didn’t work, so there was no way to decrypt files once encrypted (it was effectively a wiper). But the worm worked very well, and more than 200,000 computers were affected in around 150 countries in just a few days. Three months after saving the world, he was arrested by the FBI. This is the typically convoluted world navigated by a ‘hacker’ – a world we try to unravel in this series of Hacker Conversations. The young Marcus Hutchins Hutchins diverges from many hackers in having no desire to change something; merely an intense desire to understand how it works. “Not knowing more about how something works bothers me,” he explains. But although he doesn’t wish to change the thing he needs to understand, his understanding leads to an appreciation of how things work, or don’t work, or aren’t supposed to work but do.Advertisement. Scroll to continue reading. “I will literally be like, ‘Oh, I want to see how this electrical system works’. And then I’ll be like, ‘Okay, I understand the electronics; now I want to see how it works on a physical level, and then on a quantum physics level’, and I just sort of end up spiraling – just wanting to know more and more about how any specific system works.” This intensity may partially be an effect of neurodiversity, a very common condition among natural hackers. “If I get interested enough in a task, I find it very easy to just commit a lot of time to that task. So of course, the flip side of that is, if I’m not interested in said task, I am basically useless.” The natural effect of this type of polarization is a deep understanding of some subjects, but little knowledge of others. He was given his first computer at 13. This was something that interested him. In the next few years, he taught himself VB, PHP, C, C++, and Assembly. But at a cost to his other school studies. “I was just this very young kid with too many skills in a certain area and no productive outlet for them. Academic qualifications were already out of the window. I was basically just a writer of code.” Like attracts like. This combination gravitated toward other coders with a similar lack of academic qualification or predefined direction. “I started getting involved on cybercrime forums quite early on. My skill was primarily coding, so I ended up writing hacks rather than doing hacking.” This explains his reluctance to think of himself as a hacker – he worked with and perhaps for hackers, but was never personally engaged in hacking. “I got involved in selling software for hackers to use, either to assist in hacks or to perform hacks. So, I ended up becoming part of a cybercrime group where I was their professional malware developer – my job was to maintain the back doors and the code responsible for subverting antiviruses and bypassing security systems.” This journey started while he was still at school. He occasionally shut down the school computers, just briefly, and just for fun. In 2013, he started to write an anonymous blog called MalwareTech focused on how malware works, and included within it proof of concepts. The blog became popular for both cybersecurity professionals and cybercriminals; but the criminals were willing to pay for his proof of concepts – and he didn’t stop them. At no point did he consciously decide to be ‘bad’. “There was never a distinct line where I could think, ‘This is OK, but that isn’t’. Things aren’t black and white – it’s all just a big scale of gray,” he comments. To begin with, he had a skill, and he was just selling that skill. There was a disconnect between what he did with his skill, and what they did with his skill. “From my perspective, I’m writing some code, which I then sell to a person, and then I don’t see it again after that. That’s just kind of the way that scene works.” He was still a young kid. “I didn’t really think about, ‘Where does the code go after I sell it? What do they do with it?’ I wasn’t stupid, and I could guess it wasn’t anything good. But not directly knowing what was happening removed a lot of the psychological barrier that would have existed if I was doing it myself – like robbing a bank or mugging someone. That would be very clear: I am doing something bad here that hurts another person.” At the time, he felt it was more like re-selling his kitchen knife. “What are they going to do with my kitchen knife? Are they going to cut vegetables or cut a person? Just the lack of any clean knowledge of what is actually going on allows you to emotionally distance yourself for a bit.” But the distancing didn’t hold. Over time he got too close to some of the organizations who were using his code, and he began to see the harm his code was causing. “I just didn’t like knowing that I was responsible for those kinds of things. I decided to cut ties and look for a legitimate job.” The maturing Marcus Hutchins hero There is an amorality in the actions of most young hackers. But there comes a point where these young hackers make a conscious choice between morality (the white) and immorality (the black). Hutchins was no different; and this was that time. For some, the decision to choose morality is based on parental upbringing; for others it is a religious background. For Hutchins it seems to be an innate understanding of the difference and choice between good and bad that grew with his own growing maturity. He chose to eschew the harmful side of hacking. Just as MalwareTech had introduced him to the criminal element, so it had also introduced him to cybersecurity professionals. In 2016 he found a position as a research and development lead for a firm in Los Angeles; and moved to the US. This was a year before the original WannaCry outbreak, and he was now a legitimate cybersecurity professional. Remember the effect of his neurodiversity – if he found a task interesting, he was capable of deep focus. WannaCry interested him. “WannaCry was a big deal at the time. Unrelated organizations were going down all round the country, and nobody really knew why. That sort of interested me, because it was nothing like anything I had seen before.” WannaCry was based on a leaked NSA exploit called EternalBlue which scanned the internet for any computer with an available SMB port, and opened a backdoor called DoublePulsar. The hackers used these to locate accessible targets and then to deliver their own ransomware. The result was ransomware that copied itself, unaided, from computer to computer in a chain reaction across the internet. The exploit originated from the NSA and worked. The ransomware was coded by the hackers and only partly worked: the encryption worked, but the decryption failed – making it a ferociously aggressive and destructive wiper. “As I’m analyzing this malware, I noticed there’s an unregistered domain in the code.” This, in itself, is not unusual. Researchers who find such domains within malware register them, because it helps to monitor and understand the malware. So, Hutchins registered iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea dot com for $10.69. Able to see what was happening, he found the site was getting hammered, receiving tens of thousands of queries every couple of minutes. “So, I’m looking for a way to understand what it’s doing and stop it, when I learn that WannaCry itself had stopped. The domain was the kill switch simply by being on the internet and responding to the queries with a 200 status code” [the way a receiving web server tells the source the message has been received]. Nobody really understands why the malware was coded this way","https:\u002F\u002Fwww.securityweek.com\u002Fhacker-conversations-marcus-hutchins\u002F","https:\u002F\u002Fwww.securityweek.com\u002Fwp-content\u002Fuploads\u002F2026\u002F08\u002FHacker-Conversations-Marcus-Hutchins.jpeg","2026-08-11T10:00:00+00:00","2026-08-11T10:00:08.969217+00:00",7,[18,21],{"name":19,"type":20},"Marcus Hutchins","threat_actor",{"name":22,"type":23},"MalwareTech","product","e7b231c8-5f79-4465-8d38-1ef13aea5a14",{"id":24,"icon":26,"name":27,"slug":28},null,"Threat Intelligence","threat-intelligence",[30,35,40],{"category":31},{"id":32,"icon":26,"name":33,"slug":34},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",{"category":36},{"id":37,"icon":26,"name":38,"slug":39},"c5eccf7c-abbc-4bd3-bbed-e6da5cba8e73","Incident Response","incident-response",{"category":41},{"id":24,"icon":26,"name":27,"slug":28},[43],{"type":34,"value":44,"context":45},"WannaCry","Destructive cryptoworm for which Marcus Hutchins found a kill switch."]