ICANN Issues Provisional Clearance for GalComm

Domain Registrar GalComm Under Scrutiny Following Malware Network Allegations

Picture of security lock icon

The Critical Role of Domain Registrars in Internet Security

In the vast and interconnected landscape of the internet, domain registrars play an indispensable role, acting as the gateway through which individuals and organizations establish their online presence. They are the entities responsible for managing the reservation of internet domain names, linking them to specific IP addresses, and ensuring the smooth functioning of global web traffic. However, with this critical function comes significant responsibility, particularly in the ongoing battle against cybercrime. Domain registrars are often the first line of defense in preventing malicious actors from establishing footholds on the internet, making their policies, oversight, and responsiveness central to maintaining a secure online environment for everyone.

The constant evolution of cybersecurity threats means that registrars must remain vigilant, implementing robust systems to identify and mitigate the registration and use of domains for nefarious purposes, such as phishing, malware distribution, and command-and-control operations. When allegations of complicity or negligence arise, they not only threaten the reputation of the specific registrar but also raise broader questions about internet governance and the collective effort to safeguard digital ecosystems. This intricate balance between facilitating legitimate online activity and combating digital threats forms the backdrop for the recent controversy involving ICANN-accredited domain registrar GalComm and the cybersecurity firm Awake Security.

Awake Security Unveils a Massive Malware Network

The internet community was stirred in June following the release of a comprehensive report by Awake Security, a prominent cybersecurity intelligence firm. This groundbreaking investigation exposed a sprawling network dedicated to distributing malware, compromising countless user devices, and facilitating illicit activities across the globe. The report, which delved deep into the infrastructure underpinning these malicious operations, implicated numerous domain names allegedly utilized within the network. A significant portion of these domains, according to Awake Security’s findings, were registered through GalComm, an ICANN-accredited registrar.

Awake Security’s research went beyond merely identifying the domains; it questioned the role of GalComm in these illicit activities. The report raised serious inquiries into whether the registrar was actively involved in enabling the malware network, or, at the very least, if it was turning a blind eye to the suspicious activities taking place through its services. Such an accusation carries substantial weight, potentially implying a failure in due diligence, a lack of robust security protocols, or even a deliberate disregard for the consequences of hosting malicious infrastructure. The detailed analysis presented by Awake Security pointed to a systemic issue, prompting immediate concern among cybersecurity experts and internet governance bodies alike regarding the responsibility of registrars in policing their domain portfolios and actively combating the misuse of their services by threat actors.

ICANN’s Initial Scrutiny Finds No Corroboration

Responding swiftly to the serious allegations, the Internet Corporation for Assigned Names and Numbers (ICANN), the global non-profit organization responsible for coordinating the maintenance and procedures of several databases related to the namespaces and numerical spaces of the internet, initiated its own review of GalComm. ICANN’s role is critical in maintaining the stability and security of the internet’s unique identifier systems, including accrediting and overseeing domain registrars worldwide. Given the gravity of Awake Security’s report, an investigation into GalComm’s compliance with its contractual obligations to ICANN, particularly concerning the prevention of abusive registrations, became imperative.

However, the initial findings from ICANN’s Security, Stability and Resiliency (SSR) team presented a stark contrast to Awake Security’s conclusions. According to communications, ICANN’s team has so far been “unable to corroborate the findings Awake Security presented.” This statement suggests that, based on their internal review and methodology, ICANN did not find sufficient evidence to substantiate Awake Security’s claims of GalComm’s involvement or negligence in facilitating the malware network. Furthermore, ICANN’s review indicated that “it does appear that Awake Security had an inaccurate picture of the total domains under management by GalComm.” This discrepancy in data could significantly impact the perceived scale of the issue and the direct culpability attributed to the registrar. Despite these initial findings, ICANN has made it clear that its investigation into the matter remains ongoing, underscoring the complexity and the need for thoroughness in such high-stakes cybersecurity inquiries.

GalComm Vehemently Denies Allegations

From the moment Awake Security’s report surfaced, GalComm has maintained a strong stance of innocence, vehemently refuting all allegations leveled against it. Through its legal counsel, the registrar promptly contacted ICANN to formally dispute the contents and implications of Awake Security’s report. This proactive engagement with the governing body demonstrates GalComm’s intent to clear its name and address the accusations within the established framework of internet governance. Simultaneously, GalComm also reached out to Awake Security directly, formally requesting a retraction of the report, underscoring the severe impact such public accusations can have on a business’s reputation and operational integrity within the competitive domain name industry.

The company’s defense highlights the inherent challenges faced by domain registrars in monitoring every single registration among potentially millions of domains. While registrars are contractually obligated to combat abuse, distinguishing legitimate domain usage from malicious intent on a massive scale is a complex task. GalComm’s refutation suggests that either the allegations are factually incorrect, or that any identified malicious activity occurred despite their best efforts to comply with industry standards and ICANN policies. The registrar’s position underscores the critical debate around the extent of a registrar’s responsibility versus its practical capabilities in an ever-evolving threat landscape. The ongoing nature of ICANN’s investigation will be crucial in determining whether GalComm met its obligations or if broader policy adjustments are necessary for all registrars.

The Contentious Issue of Communication Prior to Publication

An intriguing and somewhat contentious aspect of this unfolding case revolves around the communication — or lack thereof — between the parties involved prior to the public release of Awake Security’s report. Awake Security asserts that it made multiple attempts to contact GalComm before publishing its detailed findings on the malware network. This practice is a standard protocol in responsible investigative journalism and cybersecurity research, allowing accused parties an opportunity to respond, clarify, or rectify issues before public disclosure. Such attempts demonstrate due diligence and can help ensure the accuracy and fairness of a report.

However, GalComm explicitly refutes these claims, stating that it did not receive any communication attempts from Awake Security prior to the report’s publication. This direct contradiction introduces a layer of complexity to the narrative. While it might be challenging to outright disbelieve a reputable cybersecurity firm’s claim of attempting contact, it is equally plausible that such communications, if they occurred, may not have reached the intended recipients within GalComm due to various reasons—ranging from technical glitches like spam filters, incorrect contact details, or internal communication breakdowns. The author finds it difficult to imagine Awake Security would not attempt to contact the registrar; a more probable scenario for GalComm’s defense is that it didn’t actually receive the communications. This dispute over pre-publication contact highlights the often-fraught relationship between security researchers and the entities they investigate, where miscommunication can lead to heightened tensions and further disputes, irrespective of the underlying facts of the case.

Adding another twist to the communication saga, there’s a disagreement regarding contact between Awake Security and ICANN itself. Russ Weinstein, ICANN’s Vice President of Accounts and Services, reportedly informed GalComm that Awake Security had not contacted ICANN concerning their findings. Yet, Awake Security has communicated directly with Domain Name Wire, asserting that it did, in fact, establish contact with ICANN on August 6th. This further muddies the waters, suggesting potential internal communication gaps within ICANN or a misunderstanding among the parties involved, complicating the already intricate investigation.

Awake Security Stands Firm: Independent Validation and Evolving Threats

Awake stands by the findings in our report. As a result of our analysis, Google took down numerous extensions from the Chrome App Store. Moreover, as our research showed, reputation block lists (RBLs) are ineffective for this particular type of campaign due to the evasive techniques used by attackers designed specifically to bypass reputation-based security systems. It has also been more than 2 months at this point since our research was released, and as you would expect, the attackers have since changed their tools and tactics.

We would also like to point out that Awake did in fact communicate with ICANN on August 6th but it appears that Mr. Weinstein is not aware of this. We are reaching out to him to share our prior correspondence with ICANN.

In a powerful statement issued to Domain Name Wire, Awake Security reiterated its unwavering confidence in the accuracy and thoroughness of its original report. The cybersecurity firm highlighted a significant piece of independent corroboration: as a direct consequence of their analysis and subsequent engagement, Google took decisive action, removing numerous extensions from its Chrome App Store. This move by a major tech giant like Google lends considerable weight to Awake’s findings, suggesting a degree of independent validation that transcends the disputes with GalComm or ICANN’s initial inability to corroborate.

Awake Security further elaborated on the sophisticated nature of the threats uncovered, explaining why traditional security measures like Reputation Block Lists (RBLs) proved ineffective against this particular malware campaign. RBLs typically rely on known malicious IP addresses or domains to block traffic. However, modern threat actors employ highly evasive techniques—such as domain fluxing, fast flux DNS, and rapidly rotating infrastructure—specifically designed to bypass these reputation-based systems. This constant cat-and-mouse game between attackers and defenders means that security paradigms must continually evolve to keep pace. Awake’s report not only exposed the network but also illuminated the advanced methodologies employed by these malicious entities, providing crucial insights into the current cybersecurity landscape.

Acknowledging the passage of time, Awake Security pointed out that more than two months had elapsed since their research was first released. As expected in the dynamic world of cyber warfare, the attackers implicated in the report have since adapted their tools and tactics. This constant evolution underscores the urgent need for swift action and collaborative intelligence sharing in the cybersecurity community, as delays can provide threat actors with ample opportunity to retool and continue their operations undetected.

Finally, Awake Security directly addressed the discrepancy regarding its communication with ICANN. Contrary to ICANN Vice President Russ Weinstein’s apparent unawareness, Awake firmly stated that it had indeed communicated with ICANN on August 6th. The firm indicated its intention to proactively reach out to Mr. Weinstein to share their prior correspondence, aiming to resolve the communication disconnect and ensure all relevant information is considered in ICANN’s ongoing investigation. This commitment to transparency and direct engagement highlights Awake Security’s dedication to its findings and its role in fostering a safer internet.

The Broader Implications for Internet Governance and Digital Security

This evolving dispute between Awake Security, GalComm, and ICANN transcends the specifics of one registrar or one malware network; it brings to the forefront critical questions about internet governance, registrar accountability, and the collective responsibility to secure the digital realm. The case highlights the ongoing tension between facilitating open access to domain registration and the imperative to prevent the abuse of internet infrastructure for criminal purposes. It forces a re-evaluation of the mechanisms currently in place for identifying, reporting, and remediating malicious domain registrations.

For ICANN, the investigation into GalComm serves as a test of its enforcement capabilities and its commitment to the security and stability of the internet. The outcome could set precedents for how registrars are expected to monitor their domain portfolios and respond to credible reports of abuse. It may also lead to a re-examination of registrar accreditation agreements and the penalties for non-compliance. Beyond GalComm, the incident underscores the need for enhanced collaboration between cybersecurity researchers, domain registrars, and governing bodies. A fragmented approach, characterized by miscommunications and disputes over data, only serves to benefit threat actors who exploit these cracks in the defense.

Ultimately, the digital security of internet users worldwide hinges on the integrity of the domain name system. Transparency, clear lines of communication, and robust enforcement mechanisms are paramount. As ICANN continues its investigation, the global internet community will be watching closely, hoping for a resolution that strengthens the collective defenses against online threats and reinforces trust in the essential infrastructure that underpins our digital lives.