[Не WannaCryем единым славен] Остановивший вирус WannaCry британец признался в создании и продаже вредоносного ПО - вируса Kronos

отметили
48
человек
в архиве
[Не WannaCryем единым славен] Остановивший вирус WannaCry британец признался в создании и продаже вредоносного ПО - вируса Kronos

Нейтрализовавший вирус WannaCry британский компьютерный эксперт Маркус Хатчинс признался в создании программы, способной считывать банковские данные, сообщает газета Telegraph со ссылкой на заявление прокурора Дэна Коухига в ходе судебного слушания.

По данным издания, адвокат программиста при этом подчеркнула, что он планирует заявить о своей невиновности по каждому из шести случаев создания вредоносных программ. «Он признался, что был создателем вируса Kronos, и обозначил, что продал его», — цитирует газета слова прокурора.

Ранее суд Лас-Вегаса установил залог в 30 тысяч долларов за освобождение Хатчинса.

 

Сотрудники Федерального бюро расследований США арестовали эксперта по компьютерной безопасности Маркуса Хатчинса, который в мае нашел «выключатель» в глобальном вирусе WannaCry, благодаря чему программа была обезврежена.

Специалист из Великобритании был задержан после конференции по компьютерной безопасности, которая состоялась в конце июля в Лаг-Вегасе. Хатчинса обвиняют в распространении вируса Kronos, с помощью которого злоумышленники получали доступ к персональным данным пользователей, в том числе к банковским реквизитам.

Добавил suare suare 5 Августа 2017
Комментарии участников:
suare
+1
suare, 5 Августа 2017 , url

WannaCry 'hero' to plead not guilty to accusation he wrote banking malware

US prosecutors claim Marcus Hutchins, hailed as ‘accidental hero’ for stopping major ransomware attack, admitted to creating Kronos malware targeting banks




An attorney for British security researcher Marcus Hutchins says he has ‘tremendous community support’. Photograph: Frank Augstein/AP

The British security researcher who stopped a global ransomware attack admitted to police that he wrote the code of a malware that targeted bank accounts, US prosecutors said during a hearing on Friday, but his attorneys said that he planned to plead not guilty.

Marcus Hutchins, the 23-year-old hailed as a hero for stopping the WannaCry ransomware attack, is accused of helping to create, spread and maintain the banking trojan Kronos between 2014 and 2015 and is facing six counts of hacking-related charges from the US Department of Justice (DoJ), according to a recently unsealed indictment.

A judge ruled on Friday that Hutchins – who had been in Las Vegas for the annual Def Con hacking conference – could be released on $30,000 bail. The judge said the defendant was not a danger to the community nor a flight risk and ordered him to remain in the US with GPS monitoring.

Dan Cowhig, the prosecutor, argued in federal court that Hutchins should not be freed because he is a “danger to the public”, adding: “He admitted he was the author of the code of Kronos malware and indicated he sold it.”

Briton who stopped WannaCry attack arrested over separate malware claims

Read more


As part of a sting operation, undercover officers had bought the code from Hutchins and his co-defendant, who is still at large, Cowhig said in court. The prosecutor said there is also evidence from chat logs between Hutchins and the co-defendant, revealing that Hutchins complained about the money he received for the sale.

After the hearing, Adrian Lobo, Hutchins’ defense attorney, said: “We intend to fight the case.”

She added: “He has dedicated his life to researching malware, not to trying to harm people.”

The attorney also told reporters that Hutchins’ supporters were raising money for his bond and that he should be released on Monday.

“He has tremendous community support, local and abroad and in the computer world.”

She declined to comment on the specifics of the charges, but said he was “completely shocked” by the indictment and that he was “in good spirits”.

The DoJ charges relate to the Kronos malware, which is a type of malicious software used to steal people’s credentials, such as internet banking passwords.

According to the indictment, Hutchins’ co-defendant advertised the malware for sale on AlphaBay, a darknet marketplace, and sold it two months later. The indictment did not make clear if the malware was actually sold through AlphaBay.

US and European police eventually seized servers for the marketplace, which was shut down on 20 July.

Hutchins, known on Twitter as @MalwareTechBlog, gained a reputation as an “accidental hero” in May for halting the global spread of the WannaCry ransomware attack. WannaCry infected hundreds of thousands of computers worldwide in less than a day, encrypting their hard drives and asking for a ransom of $300 in bitcoin to unlock the files. The cyberattack wreaked havoc on organisations including the UK’s National Health Service, FedEx and Telefónica.

The cybersecurity researcher, working with Darien Huss from security firm Proofpoint, found and inadvertently activated a “kill switch” in the malicious software.

The kill switch was hardcoded into the malware in case the creator wanted to stop it spreading. This involved a very long nonsensical domain name that the malware makes a request to – just as if it was looking up any website – and if the request comes back and shows that the domain is live, the kill switch takes effect and the malware stops spreading.

Hutchins noticed the domain was unregistered and so bought it for $10.69, not knowing what it did at the time. It immediately started registering thousands of connections every second.

“The intent was to just monitor the spread and see if we could do anything about it later on. But we actually stopped the spread just by registering the domain,” he told the Guardian at the time.

The WannaCry malware ended up affecting more than 1m computers, but experts estimate that without Hutchins’ intervention it could have infected 10-15m computers. Hutchins was given a special recognition award at the cybersecurity SC Awards Europe for his role in halting the malware.

Lobo and the US attorney’s office did not immediately respond to requests for comment on Friday.

The Press Association contributed reporting.

----------------------------------------------------------------------

Since you’re here …

… we have a small favour to ask. More people are reading the Guardian than ever but advertising revenues across the media are falling fast. And unlike many news organisations, we haven’t put up a paywall – we want to keep our journalism as open as we can. So you can see why we need to ask for your help. The Guardian’s independent, investigative journalism takes a lot of time, money and hard work to produce. But we do it because we believe our perspective matters – because it might well be your perspective, too.


I appreciate there not being a paywall: it is more democratic for the media to be available for all and not a commodity to be purchased by a few. I’m happy to make a contribution so others with less means still have access to information.Thomasine F-R.

If everyone who reads our reporting, who likes it, helps to support it, our future would be much more secure.

magmaster
+4
magmaster, 5 Августа 2017 , url

Теперь посадят в специзолятор. Пускай ещё что нибудь изобретает. )

Юлька с н2
-4
Юлька с н2, 5 Августа 2017 , url

Крутой чувак!

свидетель из
+2
свидетель из, 5 Августа 2017 , url

Конкуренты подставили, за то, что он их WannaCry подломил.



Войдите или станьте участником, чтобы комментировать