Hacker News new | ask | show | jobs
by heipei 2232 days ago
It is 100% accidental. He registered a domain he observed being queried from his analysis system. He did not figure out what the purpose of this domain was before registering it. One of three options:

- Act as a centralised C2.

- Act as a kill-switch (this is what happened)

- Act as a dead-man-trigger, destroying the host system.

Even if the third option is not as likely as the first one, the repercussions had he been wrong would have been severe.