he did not "accidentally neuter WannaCry". He stopped WannaCry by registering the kill-switch domain. Nothing accidental about that.
> He is not a master hacker
he is a kid. what makes his experience interesting, and his story worth listening to is that he had first-hand experience with the legal system as a hacker that went too far (because he is/was a kid). that is worth more than the arm-chair analysis of law (by wannabe skript kiddies and theoretical security experts).
https://www.malwaretech.com/2017/05/how-to-accidentally-stop...
- Act as a centralised C2.
- Act as a kill-switch (this is what happened)
- Act as a dead-man-trigger, destroying the host system.
Even if the third option is not as likely as the first one, the repercussions had he been wrong would have been severe.
He was still selling banking trojans the year before, so who knows?
He didn’t know it was the kill-switch domain, seems pretty accidental to me.
The fact that just registering the domain killed WannaCry wasn't expected, but his intent was to kill the virus from the start, that's no accident.
Besides, history tells us that those malwares won't really have such "nuking" functionality. Gating it on the presence of a server is ridiculous, and would be found out eventually when the virus runs in a weird environment where, for instance, every DNS queries resolve (e.g. hotel WiFi).
Those who have watched his reverse engineering malware live streams would beg to differ.
He does have a lot of young, inexperienced followers however, who can't tell the difference and are willing to take him at his word.
Hutchins is a media creation. The hype around him and especially his portrayal as a hero is absolute fiction.