iTnews

Damballa responds to Kraken exaggeration claims

By Sue on Apr 14, 2008 4:33PM

A day after Damballa, an internet security company that focuses on targeted threats, announced the discovery of a new BotArmy named Kraken, the company released a follow-up statement to defend its findings after a number of security professionals questioned the validity of the claims.

The accusations claim that Damballa misrepresented the high number of attacks from Kraken. A blog on F-Secure's website stated, “There are many detection names for ‘Kraken': Oderoor, Bobax, Agent, and many more. We believe that there is a single group of people behind Karken, updating their malware as time goes by. It's not new; it's just a new generation of something older.”

Damballa refuted these comments: “Damballa's initial disclosure says only that ‘Kraken was first observed in winter 2007, but investigation into its origins suggests the existence of early variants as far back as late 2006.' So is Kraken new? Damballa believes it is,” a statement released by the company on April 9 stated.

Paul Royal, principal researcher at Damballa, said the heart of the issue deals with the way information security professionals identify and categorize different entities based on their available sources and their organization's focus.

“I think a lot of people have looked at this issue from a purely malware analysis point of view,” Royal told SCMagazineUS.com on Thursday. “But people are calling it all the same thing if it has similar components or has a common author.”

The reason Damballa is calling Kraken new is because, although there are similarities between Kraken and Bobax and other threats, they use different C&C domains and communicate with the C&C in a fundamentally different way, he said.

“We're not just looking at the binaries,” said Royal, “but also at network activity. There are two distinct entities. If the server controls for Bobax were taken down, Kraken would continue and likewise.”

See original article on scmagazineus.com
Got a news tip for our journalists? Share it with us anonymously here.
Copyright © SC Magazine, US edition
Tags:
claimsdamballaexaggerationkrakenrespondssecurityto

Partner Content

Alienated from your own data? You’re not alone
Promoted Content Alienated from your own data? You’re not alone
5 essential digital transformation ideas
Promoted Content 5 essential digital transformation ideas
Security "mindset shift" needed to protect organisations
Promoted Content Security "mindset shift" needed to protect organisations
The case for postponing mainframe migration has eroded
Partner Content The case for postponing mainframe migration has eroded

Sponsored Whitepapers

Planning before the breach: You can’t protect what you can’t see
Planning before the breach: You can’t protect what you can’t see
Beyond FTP: Securing and Managing File Transfers
Beyond FTP: Securing and Managing File Transfers
NextGen Security Operations: A Roadmap for the Future
NextGen Security Operations: A Roadmap for the Future
Video: Watch Juniper talk about its Aston Martin partnership
Video: Watch Juniper talk about its Aston Martin partnership
Don’t pay the ransom: A three-step guide to ransomware protection
Don’t pay the ransom: A three-step guide to ransomware protection

Events

  • iTnews Benchmark Awards 2022 - Finalist Showcase
  • 11th Annual Fraud Prevention Summit 2022
  • IoT Impact Conference
  • Cyber Security for Government Summit
By Sue
Apr 14 2008
4:33PM
0 Comments

Related Articles

  • China spied on Russian defence research institutes
  • 'White hat' hackers no longer risk prosecution by the US
  • Careful you don't unwittingly hire North Korean IT freelancers
  • Australia's ID systems 'deficient', unfit for online: review
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Kmart Australia stands up consent-as-a-service platform

Kmart Australia stands up consent-as-a-service platform

NSW digital driver's licences 'easily forgeable'

NSW digital driver's licences 'easily forgeable'

Kmart Australia re-platforms ecommerce site to AWS

Kmart Australia re-platforms ecommerce site to AWS

NBN Co's 250Mbps and gigabit growth is finally clear

NBN Co's 250Mbps and gigabit growth is finally clear

Digital Nation

Case Study: PlayHQ leverages graph technologies for sports administration
Case Study: PlayHQ leverages graph technologies for sports administration
As NFTs gain traction, businesses start taking early bets
As NFTs gain traction, businesses start taking early bets
COVER STORY: From cost control to customer fanatics, AI is transforming the contact centre
COVER STORY: From cost control to customer fanatics, AI is transforming the contact centre
The other ‘CTO’: The emerging role of the chief transformation officer
The other ‘CTO’: The emerging role of the chief transformation officer
Metaverse hype will transition into new business models by mid decade: Gartner
Metaverse hype will transition into new business models by mid decade: Gartner
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.