South Korea Backtracks On China Cyber Attack Link

The South Korean communications regulator has admitted a mistake in its early analysis of cyber attacks on a number of organisations, backtracking on a claim the hits were linked to an IP address in China.

Officials from the Korea Communications Commission (KCC) had claimed cyber attacks had been traced back to a Chinese IP, indicating to some that North Korea was the number one suspect. In the past, when North Korea was blamed for attacks on the South, it was suggested hackers were using servers in China to escape detection.

Cyber attack mistake

But today it emerged the regulator, during its investigation into the cyber attack on NongHyup Bank, found the IP address it thought was based in China was actually a virtual IP address used for internal purposes. It was only a coincidence the address matched one registered in China, Reuters reported

The finding would indicate the attackers had control of internal IP addresses.

The Commission said it was still likely a single group was responsible to the attacks on six organisations.

Around 32,000 machines were thought to have been hit, according to the state-run Korea Internet Security Agency.

Further analysis on the malware, which wiped Master Boot Records of PCs, has been released from a host of security firms. FireEye found it was time-based, meaning it was launched at a specified time.

“It had evasion capabilities. The malware also checked for AhnLabs anti-virus—a Korean product—and disabled it. This indicates that the attackers were explicitly targeting Korea,” the company wrote in a blog post.

“In the samples we analysed, “HASTATI” and “PRINCPES” were the two strings used by the malware. It is interesting to note that both these keywords seem to reference Roman armies. The PRINCPES string seems to be a spelling mistake and we speculate that it was actually a reference to the word ‘Principes’.”

Are you a security expert? Try our quiz!

Thomas Brewster

Tom Brewster is TechWeek Europe's Security Correspondent. He has also been named BT Information Security Journalist of the Year in 2012 and 2013.

Recent Posts

Craig Wright Sentenced For Contempt Of Court

Suspended prison sentence for Craig Wright for “flagrant breach” of court order, after his false…

2 days ago

El Salvador To Sell Or Discontinue Bitcoin Wallet, After IMF Deal

Cash-strapped south American country agrees to sell or discontinue its national Bitcoin wallet after signing…

2 days ago

UK’s ICO Labels Google ‘Irresponsible’ For Tracking Change

Google's change will allow advertisers to track customers' digital “fingerprints”, but UK data protection watchdog…

2 days ago

EU Publishes iOS Interoperability Plans

European Commission publishes preliminary instructions to Apple on how to open up iOS to rivals,…

3 days ago

Momeni Convicted In Bob Lee Murder

San Francisco jury finds Nima Momeni guilty of second-degree murder of Cash App founder Bob…

3 days ago