Marcus Hutchins
Principal Threat Researcher
Marcus Hutchins is a Principal Threat Researcher at Expel, where he helps organizations understand and defend against malware threats. He’s the founder of MalwareTech, a blog with a strong security professional following. His research caught the attention of the industry in 2017 when he was identified as the researcher who registered a domain that halted the spread of the WannaCry ransomware attack.
Posts by Marcus Hutchins
Threat intel | 17 min read
SynkLoader: when you throw in everything but the kitchen sinkDiscover a new malware family, SynkLoader. See how we reverse-engineered its phishing tactics to expose its attack chain.
Threat intel | 19 min read
Not very gentlemanly: Analyzing a zero-day exploit used by The Gentlemen ransomware to disable targets’ EDRsHow the threat group used a zero-day vulnerability to disable the target's EDR, preventing it from intervening in their ransomware attack.
Threat intel | 21 min read
Inside Lazarus: How North Korea uses AI to industrialize attacks on developersExpel is tracking a North Korean (DPRK) state-sponsored APT group. This group is targeting Web3 developers to steal cryptocurrency and NFTs.
Threat intel | 13 min read
ClearFake gets more evasive with new living off the land (LOTL) techniquesClearFake's latest campaign uses fake CAPTCHAs and social engineering trick victims into installing malware, and it's getting more evasive.
Threat intel | 7 min read
Along for the ride: When legitimate software becomes a signed malware loaderAnalyzing a highly evasive malware loader that exploits legitimate, signed Greenshot software through DLL sideloading. See our detailed technical analysis.
Threat intel | 7 min read
Cache smuggling: When a picture isn’t a thousand wordsWe recently observed an innovative campaign using the ClickFix attack tactic for cache smuggling. Here's what you need to know.
