Marcus Hutchins registered the domain that acted as WannaCry’s accidental kill switch.
During the WannaCry outbreak in May 2017, Hutchins, who used the online name MalwareTech, analyzed a sample of the ransomware. He noticed that the malware contacted a long, previously unregistered domain name. Hutchins registered the domain and found that the malware stopped spreading when the connection succeeded.
The domain was not a complete cure. It did not remove the ransomware from already infected computers, and later variants used different behavior. However, the discovery sharply reduced the spread of the original version and gave organizations valuable time to patch systems and respond.
Hutchins was working as a security researcher at the time. His role became widely known because the kill-switch discovery happened during a fast-moving global incident. The episode also illustrates why malware analysts inspect network requests and other seemingly unusual code behavior.