South Korea Backtracks On China Cyber Attack Link

The South Korean communications regulator has admitted a mistake in its early analysis of cyber attacks on a number of organisations, backtracking on a claim the hits were linked to an IP address in China.

Officials from the Korea Communications Commission (KCC) had claimed cyber attacks had been traced back to a Chinese IP, indicating to some that North Korea was the number one suspect. In the past, when North Korea was blamed for attacks on the South, it was suggested hackers were using servers in China to escape detection.

Cyber attack mistake

But today it emerged the regulator, during its investigation into the cyber attack on NongHyup Bank, found the IP address it thought was based in China was actually a virtual IP address used for internal purposes. It was only a coincidence the address matched one registered in China, Reuters reported

The finding would indicate the attackers had control of internal IP addresses.

The Commission said it was still likely a single group was responsible to the attacks on six organisations.

Around 32,000 machines were thought to have been hit, according to the state-run Korea Internet Security Agency.

Further analysis on the malware, which wiped Master Boot Records of PCs, has been released from a host of security firms. FireEye found it was time-based, meaning it was launched at a specified time.

“It had evasion capabilities. The malware also checked for AhnLabs anti-virus—a Korean product—and disabled it. This indicates that the attackers were explicitly targeting Korea,” the company wrote in a blog post.

“In the samples we analysed, “HASTATI” and “PRINCPES” were the two strings used by the malware. It is interesting to note that both these keywords seem to reference Roman armies. The PRINCPES string seems to be a spelling mistake and we speculate that it was actually a reference to the word ‘Principes’.”

Are you a security expert? Try our quiz!

Thomas Brewster

Tom Brewster is TechWeek Europe's Security Correspondent. He has also been named BT Information Security Journalist of the Year in 2012 and 2013.

Recent Posts

EU Widens Investigations Into Chinese Imports, Subsidies

After the United States imposes 100 percent tariffs on certain Chinese goods, Europe widens its…

17 hours ago

Reddit Deal With OpenAI Gives ChatGPT Access To Content

OpenAI strikes deal with Reddit to train its AI tech on user posts and give…

18 hours ago

Microsoft Invests 4 Billion Euros In France For AI, Cloud

Global spending spree from Microsoft continues, with huge investment for new data centre to drive…

22 hours ago

Toshiba Axes 4,000 Staff In Post-Delisting Restructuring Operation

Workforce blow. Newly privatised Toshiba has embarked on a 'revitalisation plan' that will entail the…

2 days ago

European Union Opens Child Safety Probe Into Meta

European Commission opens an official child safety investigation into Facebook and Instagram-owner Meta Platforms

2 days ago