All of this is outside my experience, so I have to ask - how does the attack, as described, prove HutHos is the perpetrator?
The poster was able to find the HutHos site owner's full information "in a few minutes", due to "poor operational security practices." Doesn't this raise the possibility that the HutHos server was compromised by the malware's true owner?