Kraken
Home > Security Definitions - Kraken
SearchSecurity.com Definitions (Powered by WhatIs.com)
EMAIL THIS
LOOK UP TECH TERMS Powered by: WhatIs.com
Search listings for thousands of IT terms:
Browse tech terms alphabetically:
A B C D E F G H I J K L M N O P Q R S T U V W X Y Z #

Kraken



Word of the Day
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


DEFINITION - Kraken is the name given to a family of malware that's currently being used to create what the security firm Damballa has called "the world's largest botnet." Like many botnets, Kraken is principally used to send spam. Single bots infected with Kraken malware have been recorded sending up to 500,000 spam email messages in a day.

Kraken is another variant of polymorphic malware, which constantly changes to avoid detection and removal. Kraken appears as an image file to its victims, hiding the the .exe extension from view. The actual payload of the file is encrypted. Once the file is opened, Kraken copies itself to the local machine, restarts and then deletes the original copy. The botnet created with Kraken demonstrates considerable resiliency, using built-in redundancy features to automatically generate new domain names if the botmaster's server is shut down or disabled.

To date, Damballa estimates that Kraken has infected over 400,000 machines, including those of at least 50 of the Fortune 500. Damballa also reports that the malware is undetectable by the antivirus software installed on over 80 percent of infected machines.

LAST UPDATED: 09 Apr 2008

Read more about Kraken:
- Dennis Fisher reported that Kraken botnet had ballooned to dangerous levels.
- Kelly Jackson Higgins wrote about the world's biggest botnet at DarkReading.com.
- Brian Krebs investigates how Damballa gathered its data.


Do you have something to add to this definition? Let us know.
Send your comments to techterms@whatis.com


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


RELATED CONTENT
New defenses for automated SQL injection attacks
By automating SQL injection attacks, hackers have found a way to expedite the process of finding and exploiting vulnerable websites. The old defenses...
Information security book excerpts and reviews
Visit the Information Security Bookshelf for book reviews and free chapter downloads.
Yahoo, McAfee to warn users of dangerous websites
Websites suspected of spreading malicious programs or spamming and phishing campaigns will be highlighted in search results.

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
bot worm  (SearchSecurity.com)
A bot worm is a self-replicating malware program that resides in current memory, turns infected computers into zombies (or bots) and transmits itself...
cache poisoning  (SearchSecurity.com)


TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineWebcastsWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts