South Korea tracks 'source of hacking' to Chinese address

South Korea tracks 'source of hacking' to Chinese address
One of the banks in South Korea that was hit by hackers.

A Chinese internet address was the source of a cyberattack on one company hit in a massive South Korean network shutdown that affected 32,000 computers at six banks and media companies, initial findings indicated today.

It is too early to assign blame – internet addresses can easily be manipulated and the investigation could take weeks.

But suspicion for yesterday’s shutdown quickly fell on North Korea, which has threatened Seoul and Washington with attack in recent days because of anger over UN sanctions imposed for its February 12 nuclear test.

South Korean regulators said they believe the attacks came from a “single organisation,” but they have still not finished investigating what happened at the other companies.

Experts say hackers often attack via computers in other countries to hide their identities.

South Korea has previously accused North Korean hackers of using Chinese addresses to infect their networks.

Seoul believes North Korea runs an internet warfare unit aimed at hacking US and South Korean government and military networks to gather information and disrupt service.

The attack yesterday caused computer networks at major banks and TV broadcasters to crash simultaneously.

It paralysed bank machines across the country and raised fears that the heavily internet-dependent society was vulnerable.

A Chinese address created the malicious code in the server of Nonghyup bank, according to an initial analysis by the state-run Korea Communications Commission, South Korea’s telecom regulator.

Investigators are analysing the log-in records and the malicious code collected from the infected servers and computers.

It could take at least four to five days for the infected computers to recover fully, and experts say the investigation could take weeks.

South Korean regulators have also distributed vaccine software to government offices, banks, hospitals and other institutions to prevent more outages.

In an indication of the high tension on the Korean Peninsula, South Korean media reported that North Korea sounded air-raid warnings in radio broadcasts this morning as part of military drills.

The network paralysis took place just days after North Korea accused South Korea and the US of staging a cyberattack that shut down its websites for two days last week.

Loxley Pacific, the Thailand-based internet service provider, confirmed the North Korean outage but did not say what caused it. South Korea denied the allegation.

The attack may have also extended to the US. Greg Scarlatoiu, executive director of the US-based Committee for Human Rights in North Korea, said he discovered early yesterday that their website had been hacked.

They have yet to establish who was behind it but strongly suspect it came from North Korea.

The South Korean shutdown did not affect government agencies or sensitive targets such as power plants or transport systems, and there were no immediate reports that bank customers’ records were compromised, but the disruption froze part of the country’s commerce.

Some customers were unable to use the debit or credit cards that many rely on more than cash.

At one Starbucks in downtown Seoul, customers were asked to pay for their coffee in cash, and queues formed outside bank machines.

Broadcasters KBS and MBC still did not have full computer use today, but the shutdown did not affect TV broadcasts.

“If it plays out that this was a state-sponsored attack, that’s pretty bald faced and definitely an escalation in the tensions between the two countries,” said James Barnett, former chief of public safety and homeland security for the US Federal Communications Commission.

More in this Section

Boris Johnson to tell Merkel and Macron there must be new Brexit dealBoris Johnson to tell Merkel and Macron there must be new Brexit deal

Dozens feared dead or wounded after explosion at Kabul wedding hallDozens feared dead or wounded after explosion at Kabul wedding hall

Detectives given extra 36 hours to quiz suspects in death of police officerDetectives given extra 36 hours to quiz suspects in death of police officer

Teenager on murder charge after lawyer stabbed to death in UKTeenager on murder charge after lawyer stabbed to death in UK


Katarina Runske owns Anna B’s bookshop in Schull, Co Cork. She is originally from Stockholm in Sweden and also owns and runs Grove House restaurant and rooms in the West Cork village.We Sell Books: ‘It is a great lifestyle and I am very fortunate’

Five things for the week ahead with Des O'Driscoll.Five things for the week ahead

From Liverpool’s beat-pop to Bristol’s trip-hop, Irish writer Karl Whitney explains the distinctive musical output of individual cities in the UK, writes Marjorie Brennan.Sounds of the City: The musical output of individual UK cities

As landlords’ enclosures of villages and commonages during England’s industrial revolution drove landless countrymen into the maws of the poet William Blake’s “dark Satanic mills”, a romantic nostalgia for the countryside began to grow.Damien Enright: Great writers took inspiration from walking

More From The Irish Examiner