Computer Networks in South Korea Are Paralyzed in Cyberattacks
Ahn Young-Joon/Associated PressSEOUL, South Korea â" Computer networks running three major South Korean banks and the countryâs two largest broadcasters were paralyzed Wednesday in attacks that some experts suspected originated in North Korea, which has consistently threatened to cripple its far richer neighbor.
The attacks, which left many South Koreans unable to withdraw money from A.T.M.âs and news broadcasting crews staring at blank computer screens, came as the Northâs official Korean Central News Agency quoted the countryâs leader, Kim Jong-un, as threatening to destroy government installations in the South, along with American bases in the Pacific.
Though American officials dismissed those threats, they also noted that the broadcasters hit by the virus had been cited by the North before as potential targets.
The Korea Communications Commission said Thursday that the disruption originated at an Internet provider address in China but that it was still not known who was responsible.
Many analysts in Seoul suspect that North Korean hackers honed their skills in China and were operating there. At a hacking conference here last year, Michael Sutton, the head of threat research at Zscaler, a security company, said a handful of hackers from China âwere clearly very skilled, knowledgeable and were in touch with their counterparts and familiar with the scene in North Korea.â
But there has never been any evidence to back up some analystsâ speculation that they were collaborating with their Chinese counterparts. âIâve never seen any real evidence that points to any exchanges between China and North Korea, â said Adam Segal, a senior fellow who specializes in China and cyberconflict at the Council on Foreign Relations,
Wednesdayâs attacks, which occurred as American and South Korean military forces were conducting major exercises, were not as sophisticated as some from China that have struck United States computers, and certainly less sophisticated than the American and Israeli cyberattack on Iranâs nuclear facilities. But it was far more complex than a âdenial of serviceâ attack that simply overwhelms a computer system with a flood of data.
The malware is called âDarkSeoulâ in the computer world and was first identified about a year ago. It is intended to evade some of South Koreaâs most popular antivirus products and to render computers unusable. In Wednesdayâs strikes, the attackers made no effort to disguise the malware, leading some to question whether it came from a state sponsor â" which tend to be more stealthy â" or whether officials or hackers in North Korea were sending a specific, clear message: that they can reach into Seoulâs economic heart without blowing up South Korean warships or shelling South Korean islands.
North Korea was accused of using both those techniques in attacks over the past three years.
The cyberattacks Wednesday come just days after North Korea blamed South Korea and the United States for attacks on some of its Web sites. The Northâs official Korean Central News Agency said last week that North Korea âwill never remain a passive onlooker to the enemiesâ cyberattacks that have reached a very grave phase as part of their moves to stifle it.â
The South Korean government cautioned that it was still too early to point the finger for Wednesdayâs problems at the North, which has been threatening âpre-emptive nuclear attacksâ and other, unspecified actions against its southern neighbor for conducting the military exercises with the United States this month and for supporting new American-led United Nations sanctions against the North.
âWe cannot rule out the possibility of North Korean involvement, but we donât want to jump to a conclusion,â said Kim Min-seok, a spokesman for the Defense Ministry.
The military raised its alert against cyberattacks, he added, and the Korea Communications Commission asked government agencies and businesses to triple the number of monitors for possible hacking attacks. South Koreaâs new president, Park Geun-hye, instructed a civilian-government task force to investigate the disruptions.
Nicole Perlroth contributed reporting from San Francisco, and David E. Sanger from Washington.
A version of this article appeared in print on March 21, 2013, on page A5 of the New York edition with the headline: Computer Networks in South Korea Are Paralyzed in Cyberattacks.