' Chinese IP used in cyber attack '

Date of publication: 22-03-2013

 

The unprecedented cyber-attack that the computer networks of large South Korean broadcasters and banks Wednesday crashed used malicious codes from China, Seoul investigators said on Thursday, raising suspicions that North Korea may be behind the attack.

The Korea Communications Commission said the malware codes from an Internet protocol address in China were found to be the cause of the cyber attack on KBS, MBC and YTN and the three banks including Shinhan.

A total of 31 servers and 32,000 Pcs were hacked, and all six institutions were apparently hacked by the same organization, said Park Jae-moon, Director-General of the network Division to the KCC.

"We have no exact evidence but the malicious codes the hard disks of the affected PC's at all institutions have harmed, and the same information in the malicious codes on all of them," he said at a press conference in Seoul.

Inca Internet, a PC security firm that to the joint cyber government-civil-military threat response team participates, also said that the message, "Hacked by Whois Team" in all malicious files collected by the bodies involved in the attack was discovered.

A senior official said with the Government confirm that the activity was coming from China, that North Korea was very suspicious to be behind the cyber-attack.

The suspicion is rooted in the history of the North with the help of Internet protocol addresses based in China for the Communist country in recent hackings and warning of potentially cyber attack last week.

Many experts on North Korea speculate that the cyber terrorists training in China.

"We have suspicions that the move can by the North and we are for tracking and analysis of the data which are open to all possibilities," said a senior official Cheong Wa Dae, without going into details.

Cheong Wa Dae also considering the launch of a strategic meeting on national cyber security participated by the related government branches, as well as the private sector, said another Cheong Wa Dae official.

According to data of the national intelligence service, has conducted six such cyber acts of terror against Pyongyang Seoul in the past five years, including a distributed denial of service (DDoS) attack on the internet sites of the South Korean Government on July 7, 2009; a similar incident DDoS in March 2011 aimed at State institutions such as the Presidential Office, the National Assembly and the media; and an attack on a conservative newspaper last June.

On Wednesday, were the Web sites and computer networks by broadcasters KBS, MBC and Nonghyup, Shinhan and YTN, along with Jeju banks simultaneously shut down at 2 pm.

While the systems of the six institutions are paralyzed, their intranets were hacked and files of those who were connected with the companies servers were removed from their hard drives.

The KCC said it would take up to five days to fully normalize the servers and systems of the institutions.

"We consider all the possibilities and we put our utmost efforts in indentifying the hacker," said Park.

To minimize the consequences of the attack, the Korea Internet and security agency is offering a free malware vaccine that can be downloaded from the website (www.boho.or.kr).

People can also use the system time and date of their CMOS change program by pressing the "F2" or "Delete" key immediately after starting up the PC as a preventive measure against malicious code, said KCC officials.

Software that the computer in real time for malicious files is checked is available for download on the Inca Web site (www.nprotect.com).

There were no further attacks, and bank transactions have are normalizing, although some devices, including ATM machines, were still not working properly as of Thursday.

Operations on broadcasters KBS, MBC and YTN were also to see improvements, but they were still not with their company mail servers for the news reporting.

' The main server is currently shut down while being restored, so that some functions, such as company news production system, email and news search are brought to a halt, "said an official of the MBC Jeonju, North Jeolla province set in.

 

Related Posts

Post a Comment

Subscribe Our Newsletter