Chinese address is 'source' of cyberattack on one company hit in South Korean network shutdown
Thursday 21 March 2013
A Chinese internet address was the source of a cyberattack on one company hit in a massive South Korean network shutdown that affected 32,000 computers at six banks and media companies, initial findings indicated today.
It is too early to assign blame - internet addresses can easily be manipulated and the investigation could take weeks.
But suspicion for yesterday's shutdown quickly fell on North Korea, which has threatened Seoul and Washington with attack in recent days because of anger over UN sanctions imposed for its February 12 nuclear test.
South Korean regulators said they believe the attacks came from a "single organisation," but they have still not finished investigating what happened at the other companies.
Experts say hackers often attack via computers in other countries to hide their identities.
South Korea has previously accused North Korean hackers of using Chinese addresses to infect their networks.
Seoul believes North Korea runs an internet warfare unit aimed at hacking US and South Korean government and military networks to gather information and disrupt service.
The attack yesterday caused computer networks at major banks and TV broadcasters to crash simultaneously.
It paralysed bank machines across the country and raised fears that the heavily internet-dependent society was vulnerable.
A Chinese address created the malicious code in the server of Nonghyup bank, according to an initial analysis by the state-run Korea Communications Commission, South Korea's telecom regulator.
Investigators are analysing the log-in records and the malicious code collected from the infected servers and computers.
It could take at least four to five days for the infected computers to recover fully, and experts say the investigation could take weeks.
South Korean regulators have also distributed vaccine software to government offices, banks, hospitals and other institutions to prevent more outages.
In an indication of the high tension on the Korean Peninsula, South Korean media reported that North Korea sounded air-raid warnings in radio broadcasts this morning as part of military drills.
The network paralysis took place just days after North Korea accused South Korea and the US of staging a cyberattack that shut down its websites for two days last week.
Loxley Pacific, the Thailand-based internet service provider, confirmed the North Korean outage but did not say what caused it. South Korea denied the allegation.
The attack may have also extended to the US. Greg Scarlatoiu, executive director of the US-based Committee for Human Rights in North Korea, said he discovered early yesterday that their website had been hacked.
They have yet to establish who was behind it but strongly suspect it came from North Korea.
The South Korean shutdown did not affect government agencies or sensitive targets such as power plants or transport systems, and there were no immediate reports that bank customers' records were compromised, but the disruption froze part of the country's commerce.
Some customers were unable to use the debit or credit cards that many rely on more than cash.
At one Starbucks in downtown Seoul, customers were asked to pay for their coffee in cash, and queues formed outside bank machines.
Broadcasters KBS and MBC still did not have full computer use today, but the shutdown did not affect TV broadcasts.
"If it plays out that this was a state-sponsored attack, that's pretty bald faced and definitely an escalation in the tensions between the two countries," said James Barnett, former chief of public safety and homeland security for the US Federal Communications Commission.
- 1 The truth about 'girl things': Three cheers for Heather Watson's honesty
- 2 Man who held up 'hire me' sign at Waterloo station returns a year later with 'I'm hiring' sign
- 5 Men behaving badly: Urinating while standing, 'manspreading' and the gendering of selfishness
Man who held up 'hire me' sign at Waterloo station returns a year later with 'I'm hiring' sign
UK weather: Snow to fall in the coming week with sub-zero temperatures to last until early February
Saudi preacher who 'raped and tortured' his five -year-old daughter to death is released after paying 'blood money'
Iraq invasion 2003: The bloody warnings six wise men gave to Tony Blair as he prepared to launch poorly planned campaign
Ellen DeGeneres leads Johnny Depp, Gwyneth Paltrow and Paul Bettany in revealing game of Never Have I Ever
Nigel Farage: NHS might have to be replaced by private health insurance
'We would evict Queen from Buckingham Palace and allocate her council house,' say Greens
French court convicts three over homophobic tweets, in case hailed as a 'significant victory' by LGBT rights campaigners
British Muslim school children suffering a backlash of abuse following Paris attacks
George Galloway condemns 'racist, Islamophobic, hypocritical rag' Charlie Hebdo at freedom of speech rally
Islamic history is full of free thinkers - but recent attempts to suppress critical thought are verging on the absurd
Excellent Salary : Austen Lloyd: OXFORD - REGIONAL FIRM - An excellent opportu...
Super Package: Austen Lloyd: BRISTOL - SENIOR CLINICAL NEGLIGENCE - An outstan...
£15000 - £50000 per annum: Recruitment Genius: Fantastic opportunities are ava...
Negotiable: Recruitment Genius: A Compute Engineer is required to join a globa...