The next one, which also started surprisingly early, was using #DynDNS hostnames for botnet command and control. That's what actually got me involved in the #infosec community (and where I met @jtk !)
DynDNS was good for C&C because they could move it around quickly, and have the bots follow. If the C&C got taken down, boom, switch to a new one. We were unintentionally helping them keep their control going.
2/?