Kraken and DynDNS

05.02.2008 By

We at DNS Inc. are committed to security, especially when it comes to the use of our services for illegal activities. Our White Hat reputation has been earned by proactively policing and cleaning our system and quickly responding to operators who report issues – law enforcement agencies locally, nationally, and internationally. We perform workshops for LEOs about how to better identify and recognize nefarious activities and we participate in various operator and security groups, forums, and lists – many of them private to the public.

Damballa, a security company which claims to protect “businesses from targeted attacks used for organized, online crime,” recently posted a research paper (PDF) regarding a “spamming botnet” called ‘Kraken’ which they claim to have “400,000 distinct victims observed daily”

In a related announcement, Damballa claims that hundreds of DynDNS hosts are being used by this botnet (PDF).

The Damballa list was a surprise to us and we diligently researched the hosts listed in this paper and found that none of them actually exist in our system. We want to assure everyone that we have researched these claims and found no DynDNS hosts are being used in conjunction with this supposed ‘botnet’.