2013 South Korea cyberattack
Template:Expand Korean Template:Campaignbox Korean Cold War In 2013, two major sets of cyberattacks on South Korean targets were attributed to North Korea.
March
On 20 March 2013, six South Korean organizations suffered a suspected cyberwarfare attack.[1] The organizations included three media companies (KBS, MBC, and YTN) and three financial institutions (The National Agricultural Cooperative Federation, Shinhan Bank, and Jeju Bank). The South Korean communications watchdog, the Korea Communications Commission, raised its alert level on cyberattacks to three on a scale of five. North Korea had been blamed for similar attacks in 2009 and 2011 and was suspected of launching this attack as well. This attack also came during a period of elevated tensions between the two Koreas, following Pyongyang's nuclear test on 12 February.[2] South Korean officials linked the incident to a Chinese IP address, which increased suspicion of North Korea because the country routinely hides its cyber-attacks by using Chinese computer addresses.[3] It was later revealed that the IP address did not originate in China but from the internal network of one of the attacked organizations.[4]
The attacks on all six organizations derived from a single entity. The networks were attacked by malicious code, rather than distributed denial-of-service (DDoS) attacks as initially suspected. The malware appeared to have used only hard drive overwrites.[5] A total of 32,000 servers and computers used by media and financial companies were damaged in the attack.[6] The Financial Services Commission of South Korea said that Shinhan Bank reported that its Internet banking servers had been temporarily blocked, and that Jeju Bank and NongHyup reported that operations at some of their branches had been paralyzed after computers were infected with viruses and their files erased. Woori Bank reported a hacking attack but said it had suffered no damage.[7]
This cyberattack caused US$750 million in economic damage.[8] Also, "[t]he frequency of cyber attacks by North Korea and rampant cyber espionage activities attributed to China are of great concern to the South Korean government."[9][verify]
June
On 25 June 2013, the Blue House (Cheong Wa Dae) and other institutions were the subject of a series of data breaches. The hackers behind this incident claimed to have leaked the personal information of 2.5 million Saenuri Party members, 300,000 military personnel, 100,000 Blue House website users, and 40,000 United States Forces Korea service members. In addition to these leaks, government websites faced hacking attempts. The attack took place on the 63rd anniversary of the outbreak of the Korean War (1950-1953), the conflict that divided the Korean Peninsula. Because the Blue House website was hacked, the personal data of 220,000 people, including 100,000 ordinary citizens and 20,000 military personnel, was exposed.[10] The Office for Government Policy Coordination website and several media servers were also affected.
While multiple groups organized these attacks, one of the distributed denial-of-service (DDoS) attacks against the South Korean government was directly linked to the "DarkSeoul" gang and the Trojan.Castov malware.[11] First identified by the cybersecurity community in 2012, the DarkSeoul malware had already been used in several high-profile cyberattacks against South Korea.
Timeline
On 25 June 2013, at approximately 9:10 AM, the Blue House website, major government institution websites, and various news servers fell victim to a series of cyberattacks, including website defacement, DDoS campaigns, and data theft. Users attempting to access the Blue House homepage were met with a photo of President Park Geun-hye alongside messages reading, "The great Kim Jong-un governor" and "All hail the unified chairman Kim Jong-un! Until our demands are met our attacks will continue. Greet us. We are anonymous". At 10:45 AM on the day of the attack, the government raised the cyber threat alert level to "noteworthy", then changed it to "warning" at 3:40 PM.[12] The Blue House issued an apology on 28 June 2013.[13]
The Ministry of Science, ICT, and Future Planning revealed on 16 July that both the March and June incidents corresponded with past hacking methods used by North Korea.[14] However, the attacked targets included a Japanese Korean Central News Agency site and major North Korean anti-South websites. The hackers had also announced that they would release information on approximately 20 high-ranking North Korean army officers, along with countless pieces of information on North Korean weaponry.
Response
Following the hacking in June, there was further speculation that North Korea was responsible for the attacks. Investigators found that "an IP address used in the attack matched one used in previous hacking attempts by Pyongyang."[15] Park Jae-moon, a former director-general at the Ministry of Science, ICT and Future Planning, said, "82 malignant codes [collected from the damaged devices] and internet addresses used for the attack, as well as North Korea's previous hacking patterns," proved that "the hacking methods were the same" as those used in the 20 March cyber attacks.[16]
Following this incident, the Korean government publicly announced that they would take charge of the "Cyber Terror Response Control Tower". Along with different ministries, the National Intelligence Service (NIS) will be responsible for building a comprehensive response system using the "National Cyber Security Measures."[17]
The South Korean government asserted a Pyongyang link in the March cyberattacks, which was denied by Pyongyang.[18] A 50-year-old South Korean man identified as Mr. Kim was suspected to be involved in the attack.[19]
Appearance in the South Korean National Geographic
The National Geographic Channel Korea listed "cyber terrorism" among its top 10 keywords of 2013 due to these attacks.[20]
Measures
- The government formed a joint civil-government-military cyber crisis response headquarters.[21]
- Security companies such as AhnLab and Hauri are implementing emergency updates or distributing dedicated vaccines to detect malware that causes problems in their products. The diagnosis given by each company is as follows.
- AhnLab - Win-Trojan/Agent.24576.JPF (JPG, JPH), Dropper/Eraser.427520[22]
- INCA Internet - ApcRunCmd.exe : Trojan/W32.Agent.24576.EAN / Othdown.exe : Trojan/W32.Agent.24576.EAO[23]
- Hauri - ApcRunCmd.exe : Trojan.Win32.U.KillMBR.24576 / Othdown.exe : Trojan.Win32.U.KillMBR.24576.A
- Symantec - Trojan.Jokra[23]
- Sophos - Mal/EncPk-ACE (aka "DarkSeoul")
See also
References
- ↑ "South Korea on alert for cyber-attacks after major network goes down" (in en). 2013-03-20. http://www.theguardian.com/world/2013/mar/20/south-korea-under-cyber-attack.
- ↑ "Cyber attack hits S Korea websites" (in en-GB). 2013-06-25. https://www.bbc.com/news/world-asia-23042334.
- ↑ "China IP address link to South Korea cyber-attack". BBC. 21 March 2013. https://www.bbc.co.uk/news/world-asia-21873017.
- ↑ "韓国のサイバー攻撃、アクセス元は社内のプライベートIPアドレス" (in ja). https://atmarkit.itmedia.co.jp/ait/articles/1303/22/news098.html.
- ↑ "Are the 2011 and 2013 South Korean Cyberattacks Related?" (in en). http://www.symantec.com/connect/blogs/are-2011-and-2013-south-korean-cyber-attacks-related.
- ↑ "Hacking attack on South Korea traced to China". 20 March 2013. https://www.cnn.com/2013/03/20/world/asia/south-korea-computer-outage/index.html.
- ↑ Choe Sang-Hun, "Computer Networks in South Korea Are Paralyzed in Cyberattacks", The New York Times, 20 March 2013.
- ↑ "Roles for Australia, Canada and South Korea". Mutual Security in the Asia-Pacific: Roles for Australia, Canada and South Korea. McGill-Queen's University Press. 2015.
- ↑ "Roles for Australia, Canada and South Korea". Mutual Security in the Asia-Pacific: Roles for Australia, Canada and South Korea. McGill-Queen's University Press. 2015.
- ↑ "북한의 사이버 공격과 우리의 사이버 안보 상황" (in ko). https://blog.naver.com/gounikorea/221236005588.
- ↑ "Four Years of DarkSeoul Cyberattacks Against South Korea Continue on Anniversary of Korean War" (in en). https://community.broadcom.com/symantecenterprise/communities/community-home/librarydocuments/viewdocument?DocumentKey=edd5c93e-7160-4bf2-a15c-f1c024feb0d7&CommunityKey=1ecf5f55-9545-44d6-b0f4-4e4a7f5f5e68&tab=librarydocuments.
- ↑ 홍, 재원; 박, 홍두 (2013-06-25). "'6·25 사이버 테러' 남도 북도 같은 날 당했다" (in ko). https://www.khan.co.kr/national/incident/article/201306252215315.
- ↑ "10만건 개인정보유출 사실로 드러나....청와대, 사과문 공지" (in ko). http://www.ddaily.co.kr/news/article.html?no=106249.
- ↑ "[속보정부 "6·25 사이버공격 북한 소행""] (in ko). 2013-07-16. https://www.khan.co.kr/it/it-general/article/201307161510071.
- ↑ "N Korea 'behind hacking attack'" (in en-GB). 2013-07-16. https://www.bbc.com/news/world-asia-23324172.
- ↑ 권, 혜진 (2013-07-16). ""'6·25 사이버공격'도 북한 소행 추정"(종합)" (in ko). https://www.yna.co.kr/view/AKR20130716134851017.
- ↑ "보도자료(과학기술정보통신부) | 과학기술정보통신부". https://www.msit.go.kr/web/msipContents/contentsView.do?cateId=mssw315&artId=1212488.
- ↑ Lee Minji (April 10, 2013). "(2nd LD) Gov't confirms Pyongyang link in March cyber attacks". Yonhap News. http://english.yonhapnews.co.kr/northkorea/2013/04/10/49/0401000000AEN20130410007352320F.HTML.
- ↑ Jeyup S. Kwaak (July 31, 2013). "Seoul Suspects South Korean Tech Executive of Helping North in Cyberattacks". The Wall Street Journal. https://www.wsj.com/articles/SB10001424127887324136204578639540757695644.
- ↑ "내셔널지오그래픽채널, ‘2013년 10대 키워드’" (in ko). Kyunghyang Shinmun. 2013-12-13. https://www.khan.co.kr/culture/tv/article/201312131601451.
- ↑ "朴대통령 전산망마비 '조속복구' 지시…범정부팀 가동" (in ko). 20 March 2013. http://www.yonhapnews.co.kr/bulletin/2013/03/20/0200000000AKR20130320167800001.HTML.
- ↑ "AhnLab" (in ko). http://www.ahnlab.com/kr/site/securitycenter/asec/asecCodeView.do?virusActionVo.virus_seq=34733.
- ↑ "[잉카인터넷 대응팀 [긴급대응]언론사 방송국, 금융사이트 부팅 불가 사고 발생 [#Update 2013. 03. 25. 03]"]. http://erteam.nprotect.com/408.
