The Canadian Press - ONLINE EDITION
South Korea: Initial investigation shows Chinese address source of cyberattack at 1 company
SEOUL, South Korea - A Chinese Internet address was the source of a cyberattack on one company hit in a massive network shutdown that affected 32,000 computers at six banks and media companies in South Korea, initial findings indicated Thursday.
It's too early to assign blame — Internet addresses can easily be manipulated and the investigation could take weeks — but suspicion for Wednesday's shutdown quickly fell on North Korea, which has threatened Seoul and Washington with attack in recent days because of anger over U.N. sanctions imposed for its Feb. 12 nuclear test.
South Korean regulators said they believe the attacks came from a "single organization," but they've still not finished investigating what happened at the other companies.
Experts say hackers often attack via computers in other countries to hide their identities. South Korea has previously accused North Korean hackers of using Chinese addresses to infect their networks.
"We do know that North Korea does route attacks through Chinese servers because that's the only way they can communicate with South Korea," Timothy Junio, a cybersecurity fellow at Stanford University's Center for International Security and Cooperation, said. "It's not surprising there's a Chinese IP address involved."
Seoul believes North Korea runs an Internet warfare unit aimed at hacking U.S. and South Korean government and military networks to gather information and disrupt service.
The attack Wednesday caused computer networks at major banks and top TV broadcasters to crash simultaneously. It paralyzed bank machines across the country and raised fears that this heavily Internet-dependent society was vulnerable. On Thursday, only one of the attacked banks, Shinhan, was fully online, officials said.
A Chinese address created the malicious code in the server of Nonghyup bank, according to an initial analysis by the state-run Korea Communications Commission, South Korea's telecom regulator.
KCC spokesman Cho Kyeong-sik said investigators are analyzing the log-in records and the malicious code collected from the infected servers and computers. It could take at least four to five days for the infected computers to recover fully, he said. Experts say the entire investigation could take weeks.
South Korean regulators have also distributed vaccine software to government offices, banks, hospitals and other institutions to prevent more outages.
In an indication of the high tension on the Korean Peninsula, South Korean media reported that North Korea sounded air-raid warnings in radio broadcasts Thursday morning as part of military drills.
The network paralysis took place just days after North Korea accused South Korea and the U.S. of staging a cyberattack that shut down its websites for two days last week. Loxley Pacific, the Thailand-based Internet service provider, confirmed the North Korean outage but did not say what caused it. South Korea denied the allegation.
The attack may have also extended to the United States. Greg Scarlatoiu, executive director of the U.S.-based Committee for Human Rights in North Korea, said he discovered early Wednesday that their website had been hacked. They have yet to establish who was behind it but strongly suspect it came from North Korea.
Several of the committee's publications, including lengthy reports with satellite imagery of North Korean prison camps, had been removed, along with biographies of their staff and board, and their policy recommendations to the Obama administration.
The South Korean shutdown did not affect government agencies or sensitive targets such as power plants or transportation systems, and there were no immediate reports that bank customers' records were compromised, but the disruption froze part of the country's commerce.
Some customers were unable to use the debit or credit cards that many rely on more than cash. At one Starbucks in downtown Seoul, customers were asked to pay for their coffee in cash, and lines formed outside disabled bank machines.
Broadcasters KBS and MBC still didn't have full computer use on Thursday, but the shutdown did not affect TV broadcasts.
The YTN cable news channel also said the company's internal computer network was paralyzed. Footage showed workers staring at blank computer screens.
KBS employees said they watched helplessly as files stored on their computers began disappearing.
Last year, North Korea threatened to attack several news companies, including KBC and MBC, over their reports critical of children's' festivals in the North.
"If it plays out that this was a state-sponsored attack, that's pretty bald faced and definitely an escalation in the tensions between the two countries," said James Barnett, former chief of public safety and homeland security for the U.S. Federal Communications Commission.
An ominous question is what other businesses, in South Korea or elsewhere, may also be in the sights of the attacker, said Barnett, who heads the cybersecurity practice at Washington law firm Venable.
"This needs to be a wake-up call," he said. "This can happen anywhere."
An official at the South's Korea Communications Commission said investigators speculate that malicious code was spread from company servers that send automatic updates of security software and virus patches.
The shutdown raised worries about the overall vulnerability to attacks in South Korea, a world leader in broadband and mobile Internet access. Previous hacking attacks at private companies compromised millions of people's personal data. Past malware attacks also disabled access to government agency websites and destroyed files in personal computers.
Seoul blames North Korean hackers for several cyberattacks in recent years. Pyongyang has either denied or ignored those charges. Hackers operating from IP addresses in China have also been blamed.
In 2011, computer security software maker McAfee Inc. said North Korea or its sympathizers likely were responsible for a cyberattack against South Korean government and banking websites earlier that year. The analysis also said North Korea appeared to be linked to a massive computer-based attack in 2009 that brought down U.S. government Internet sites. Pyongyang denied involvement.
"North Korea has almost certainly done similar attacks before," Junio said. "Part of why this wasn't more consequential is probably because South Korea took the first major incident seriously and deployed a bunch of organizational and technical innovations to reduce response time during future North Korea attacks."
South Korea has created a National Cybersecurity Center, a national monitoring sector and a Cyber Command modeled after the U.S. Cyber Command. Junio said South Korea's major antivirus firms also play a large role in stopping hacking attacks.
The shutdown comes amid rising rhetoric and threats of attack from Pyongyang over U.N. sanctions imposed for its December long-range rocket launch and February nuclear test. Washington also expanded sanctions against North Korea this month in a bid to cripple the government's ability to develop its nuclear program.
North Korea has threatened revenge for the sanctions and for ongoing U.S.-South Korean military drills, which the allies describe as routine but which Pyongyang says are rehearsals for invasion.
Last week, North Korea's Committee for the Peaceful Reunification of Korea warned South Korea's "reptile media" that the North was prepared to conduct a "sophisticated strike" on Seoul.
Lim Jong-in, dean of Korea University's Graduate School of Information Security, said North Korea was probably responsible for Wednesday's attack.
"Hackers attack media companies usually because of a political desire to cause confusion in society," he said. "Political attacks on South Korea come from North Koreans."
___
Associated Press writers Foster Klug, Youkyung Lee and Hyung-jin Kim in Seoul, Matthew Pennington and Ed Donahue in Washington and Martha Mendoza in San Jose, California, contributed to this report.
More World
- Back to Top
- Return to World
More World
(1 of 22 articles for today)
Alexander Payne debuts his black and white 'Nebraska' at Cannes Film Festival
12:05 PM 0Poll
Most Popular World
- Brave woman tried to calm London attackers and reasoned with them before police came
- Youths in Stockholm burn down restaurant, torch more than 30 cars in 4th night of rioting
- Man shot to death in Fla. while being questioned in Boston Marathon bombing investigation
- Canadian Press NewsAlert: 2 more arrested in hacking death of soldier in London
- Gay teen charged for having younger girlfriend
- 'An eye for an eye'
- Preliminary estimate puts Oklahoma tornado damage at $2 billion; 13,000 homes damaged, ruined
- Polish man gets quick face transplant in what doctors say was life-saving decision
- Bangladesh probe faults swampy land, poor building materials, heavy equipment for collapse
- Canseco accused of sex assault in Vegas; former slugger airs info on Twitter
- Massive tornado roars through Oklahoma City suburb, killing at least 51
- Search for survivors of Oklahoma tornado nearly complete, as homeowners confront devastation
- Man shot to death in Fla. while being questioned in Boston Marathon bombing investigation
- Brave woman tried to calm London attackers and reasoned with them before police came
- Phone cracked? Cool
- US woman credits 'mother's instincts' in chase of 4-year-old daughter's abductor
- Polish man gets quick face transplant in what doctors say was life-saving decision
- Umbrella-gate stirs outrage
- US zoo looking into conception mystery after birth of anteater; no male in pen
- Remote Alaska volcano continues to erupt, with lava fountains, ash plumes
- Amanda Berry, 1 of 3 women freed after held captive in Ohio home, arrives at sister's home
- Massive tornado roars through Oklahoma City suburb, killing at least 51
- Friendship with bomb suspect, complex chain of events leads to 3 being charged
- Police vow to solve shooting that wounded 19 people during Mother's Day parade in New Orleans
- Missing Pa. woman, last seen dropping off kids for school in 2002, surfaces in Fla.
- Cleveland police: Ohio captive suffered 5 miscarriages after being beaten and starved
- Jodi Arias convicted of first-degree murder, says she prefers death penalty
- Neighbours: Man in custody comforted missing girl's mom, helped search for missing US women
- Search for survivors of Oklahoma tornado nearly complete, as homeowners confront devastation
- High school baseball team lifts car to free 16-year-old girl
- Phone cracked? Cool
- The pope and the devil: Francis' obsession with Satan leads to suspicion he performed exorcism
- FBI: Man killed had become violent during questioning on Boston bombing
- Brave woman tried to calm London attackers and reasoned with them before police came
- Phone cracked? Cool
- Ray Manzarek, keyboardist and founding member of rock group The Doors, dies at 74 from cancer
- Hatchet-wielding hitchhiker who intervened in California attack arrested in NJ homicide
- Remote Alaska volcano continues to erupt, with lava fountains, ash plumes
- Argentina's 'dirty war' dictator dies
- Massive tornado roars through Oklahoma City suburb, killing at least 51
- Shady characters: Cookie Monster, Elmo accused of aggressive behaviour in Times Square
- U.S. envoy punted; Russia alleges spying
- US woman credits 'mother's instincts' in chase of 4-year-old daughter's abductor
- Up to 60 people injured when car drives into Va. parade; medical emergency possible cause
- 'Coronation Street' actor William Roache charged in UK over alleged rapes in 1967
- Coroner: 5-year-old boy shoots 2-year-old sister in US with rifle he got as a gift
- Hitler ate well, his food taster recalls
- Black bear wanders into LA-area suburbia, chases swimmers from pool, strands kids in class
- Female guards, rapidly growing in numbers, at heart of U.S. prison scandal
- Phone cracked? Cool
- US tourists swim for nearly 14 hours after boat sinks near St. Lucia
- IBM makes movie about a little boy - a very little boy - by pushing molecules around
- Friendship with bomb suspect, complex chain of events leads to 3 being charged
- Missing Pa. woman, last seen dropping off kids for school in 2002, surfaces in Fla.
Ads by Google












You can comment on most stories on winnipegfreepress.com. You can also agree or disagree with other comments. All you need to do is register and/or login and you can join the conversation and give your feedback.
Have Your Say
New to commenting? Check out our Frequently Asked Questions.
The Winnipeg Free Press does not necessarily endorse any of the views posted. By submitting your comment, you agree to our Terms and Conditions. These terms were revised effective April 16, 2010.