If he's who I think he is, I doubt his early background is that clean, despite him being a whitehat now. It is very much possible he is being held because of something related to that and not because of anything related to WannaCry. This was all before he even started running the MalwareTech blog, it's very much possible the FBI decided to look into his background or were already familiar with it prior to him arriving in or leaving the US.
That being said, it's possible that I'm mistaking him for someone else in which case I do apologize. I edited the post a bit, to clarify, the first paragraph to the best of my knowledge is certainly true, second one is based on my own speculation so take it with a grain of salt.
Yeah, like the rest of the people commenting here, right? They have all the facts.
Virustotal passive DNS shows that it was hosted for a time on the same server as his old irc, irc.voidptr.cz
https://www.virustotal.com/en/ip-address/188.190.99.148/info...
EDIT: Ah, found some old logs on google: http://www.exposedbotnets.com/2013/05/hf-elite-coding-team.h...
[08:08] <TouchMe> if i still owned this irc
[08:09] <TouchMe> i would shut it down and start overI know TouchMe is malwaretech but would be inclined to assume that BetaMonkey isn't.
TouchMe was still a malware developer though, and apparently used to run voidptr before handing it over to BetaMonkey.
If BetaMonkey==TouchMe then they were trying really hard to conceal that.
Here's a hackforums thread mentioning some other malware TouchMe was distributing though https://hackforums.net/showthread.php?tid=3786935
If I was a bad man in the security profession who was certain he was anonymous, I'd point to someone else who was a security professional on twitter when I vanished too.
It just y'know, wouldn't have been me.
I used to talk to this guy on a malware dev IRC on a daily basis, he started a blog "TouchMyMalware" which eventually evolved into Malwaretech.
This is all easily verifiable with google and archive.org.
And lol, apparently some twitter user dug up logs of him offering to sell me a rootkit for $20k https://twitter.com/jeremiahg/status/893207272154734592
"he's a fucking genius because he got us all" https://twitter.com/x0rz/status/893203106338680832
Yes. And I've had a hostile fellow once upon a time put my RL info in the whois and post a bunch of shit on it. I generally give people the benefit of the doubt when its random online public stuff until they are convicted.
The internet "evidence" is way too flimsy to be considered reasonable standards of proof imho.
Navigate to: https://web.archive.org/web/20131031200609/https://twitter.c...
Pick any of the tweets, copy the direct link to that tweet.
You'll end up with something like this: https://web.archive.org/web/20131031200609/https://twitter.c...
Now remove the archive.org part from the beginning: https://twitter.com/TouchMyMalware/status/395862786602827776
Click on the link and boom you're suddenly redirected to https://twitter.com/MalwareTechBlog/status/39586278660282777...
Here's also an archive.org link showing the account with the "TouchMe" name on it: https://web.archive.org/web/20130710045915/https://twitter.c...
Happy?
> Click on the link and boom you're suddenly redirected to https://twitter.com/MalwareTechBlog/status/39586278660282777....
> Okay, never fear! In that case I will provide you with irrefutable proof.
> Happy?
https://twitter.com/TouchMyMalware/status/893243147580473344
You proved he is Donald Trump?
I'm not trying to pick a fight here so just chill and move on. We aren't going to agree.
Yes, I'm sorry I didn't immediately realize that you were just trolling. If not, you might want to look at the parts of my post you decided not to quote.
https://twitter.com/MalwareTechBlog/status/40533646447018393...
Touchme/Marcus was a close friend of his though, one of his first articles on the site that eventually became malwaretech.com was an attempt to disprove the claim that betamonkey's malware was banking malware. This had gotten him banned from selling on hackforums, his main source of customers at the time. You have to read the article on the way back machine, for some reason he deleted it from his site later on [1].
If I were betamonkey I would be sweating pretty hard right now, his malware is also still being used and Marcus will be looking hard for someone else to drag under the bus.
[0] http://www.xylibox.com/2015/04/betabot-retrospective.html [1] https://web-beta.archive.org/web/20130625172146/http://touch... (halfway down the page)
> For anyone still into IRC, MalwareTech has partnered with sigterm.no to launch a new IRC network. It’s still fairly new so don’t expect an instant response, but everyone is welcome (socializing or just asking for help).
No everyone has already determined 'wow he did a good deed' and 'us law enforcement bad'.
The fact is he is linked to this event and a person of interest who they want to get more info from. As such it makes total sense they would detain him for some questioning searches and so on.
If you are someone who stops a crime you will also get questioned by the police. For all they know you are covering your own tracks and had a role in the crime. This is almost a cliche in movies and tv.
Yup. Law enforcement is not obliged to assume his innocence.