Marcus Hutchins became famous almost overnight in May 2017. Online he went by MalwareTech, and he’d just helped stop WannaCry from spreading by registering a domain hidden inside the ransomware’s code. That domain worked like a kill switch. Three months later, the FBI arrested him in Las Vegas. Quite a turn.
From Malware Researcher to WannaCry Hero
Before WannaCry, Hutchins already had a reputation for studying malware. Taught himself programming as a teenager, started the MalwareTech blog writing detailed technical research on malicious software, and by 2016 had moved into legitimate cybersecurity work at a Los Angeles company.
Then WannaCry happened. He noticed the ransomware contacting a strange unregistered domain, registered it himself just to monitor traffic, and that accidentally stopped the malware cold. Made him famous overnight. Also exposed his real identity, which had been hidden behind the MalwareTech name until then.
The Arrest Nobody Expected
In August 2017, the FBI arrested Hutchins while he was at the DEF CON hacking conference. Nothing to do with WannaCry though, the charges were about earlier work creating and distributing malware called Kronos and UPAS Kit, programs prosecutors said were built to steal information from infected computers, allegedly sold with the help of another person.
He initially pleaded not guilty. Case dragged on for almost two years while he stayed in the US rather than heading back to Britain. Genuinely strange situation, the same guy who’d just become famous for helping stop a major cyberattack was now facing federal charges over older hacking activity.
What Did Marcus Hutchins Plead Guilty To?
In May 2019, Hutchins pleaded guilty to two charges tied to the Kronos and UPAS Kit case. The Justice Department said he admitted creating the malware and working with an accomplice to sell it for profit.
Matters because the WannaCry story sometimes gets told like he was just a security researcher randomly arrested after saving the internet. The actual record’s more complicated. Earlier activities involved malware meant to steal banking info, and he accepted responsibility for two federal charges.
What Happened After the Case?
Sentenced in July 2019, one year of probation on top of the time already spent dealing with the case. Went back to cybersecurity work afterward, relocated permanently to Los Angeles by his own account.
He didn’t disappear either. Still publishes technical research under the MalwareTech name, focused heavily on malware analysis and security research, with recent writing on Windows internals, vulnerabilities, and AI. Still speaks publicly about cybersecurity too.
So Where Is Marcus Hutchins Now?
As of 2026, he’s still active in cybersecurity, still publishing research. Career’s basically moved from underground malware development into legitimate security work, though the earlier chapter’s impossible to fully separate from his public reputation.
That’s probably what makes his story so unusual. Not simply the anonymous hacker who stopped WannaCry, not simply the person who got arrested afterward. Both things happened, and the internet just discovered the second one right after celebrating the first.