Feeds

North and South Korea hit by cyber-blitz on Korean War anniversary

Official Nork portals knocked offline, South Korean prez and PM also KO'd

The Power of One eBook: Top reasons to choose HP BladeSystem

Both North and South Korea are under cyber attack from a group of unidentified hackers who blitzed senior government officials' websites and a group of media companies.

The website of the South Korean presidential office and prime minister's office were among the sites hit on Tuesday morning.

"The government confirms there was a cyberattack this morning by unidentified hackers that shut down several sites including the presidential Blue House, the prime minister's office and some media companies," the South Korean science ministry said in a statement reported by the Wall Street Journal.

North Korea's Korean Central News Agency, state-owned airline Air Koryo, state-owned newspaper Rodong Sinmun, and official state web portal Naenara were also knocked offline on Tuesday, CBS News reports.

The attack coincides with the anniversary of the start of the Korean War on 25 June 1950, which resulted in the division of the Korean peninsula between North and South Korea.

Most of these sites, targets of previous campaigns by hacktivist group Anonymous, are actually run from servers hosted in China. Elements of Anonymous have claimed responsibility for the attacks against the North but the situation remains confused, the BBC reports.

South Korea has raised its state of alert in response to the attacks, which are minor compared to attacks in March against South Korean banks and broadcasters that disrupted banking services. An estimated 32,000 computers were infected with malware designed to trigger at a pre-set time. The March attacks came at a time of heightened tensions on the Korean peninsula following nuclear tests by the Norks.

South Korea also suffered similar cyber attacks in 2009 and 2011.

Chris McIntosh, chief exec at ViaSat UK and a former Royal Signals officer, said that further attacks are almost inevitable. He added that others can learn from the experiences of the Koreans.

“We know this isn’t the first such attack against South Korea, and it certainly won’t be the last," McIntosh said. "Put simply, despite such attacks swiftly becoming a fact of life there is still too much evidence of an 'it couldn’t happen here' mentality."

"Organisations need to assume from the very start that their networks have already been breached by cyber criminals or worse and implement people, procedural and technological control measures based on this,” he added.

“Since an attacker will go for the lowest-hanging fruit, every point of weakness and potential interaction with the outside world needs to be identified, whether it is how information is stored; how data is moved; how the network is accessed; and, most simply, exactly what technology people are using.” ®

Update

Rik Ferguson, VP of security research at Trend Micro, said that while the attacks against North Korean targets appear to be routine DDoS assaults, the attacks against South Korean websites appear to be more focused on defacement. These involved apparent attempts to discredit Anonymous by portraying elements of the hacktivist group as responsible for attacks on South Korean websites.

"The attacks on South Korean sites appear somewhat different, less about Denial of Service and more about access, exploitation and defacement," Ferguson said. "One video posted briefly on YouTube showed an attacker using a tool call w3b_avtix apparently to connect to the website of the South Korean president, exploit a vulnerability, gain access and upload defaced content to the website."

"Everything has been done to brand the video as an "Anonymous" attack; however, one of the most vocal Twitter users (@anonsj) associated with Anonymous activity in Korea has disavowed any attacks on South Korean web sites."

Designing a Defense for Mobile Applications

More from The Register

next story
Secure microkernel that uses maths to be 'bug free' goes open source
Hacker-repelling, drone-protecting code will soon be yours to tweak as you see fit
How long is too long to wait for a security fix?
Synology finally patches OpenSSL bugs in Trevor's NAS
Roll out the welcome mat to hackers and crackers
Security chap pens guide to bug bounty programs that won't fail like Yahoo!'s
HIDDEN packet sniffer spy tech in MILLIONS of iPhones, iPads – expert
Don't panic though – Apple's backdoor is not wide open to all, guru tells us
Researcher sat on critical IE bugs for THREE YEARS
VUPEN waited for Pwn2Own cash while IE's sandbox leaked
Four fake Google haxbots hit YOUR WEBSITE every day
Goog the perfect ruse to slip into SEO orfice
Putin: Crack Tor for me and I'll make you a MILLIONAIRE
Russian Interior Ministry offers big pile o' roubles for busting pro-privacy browser
prev story

Whitepapers

Designing a Defense for Mobile Applications
Learn about the various considerations for defending mobile applications - from the application architecture itself to the myriad testing technologies.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Top 8 considerations to enable and simplify mobility
In this whitepaper learn how to successfully add mobile capabilities simply and cost effectively.
Seven Steps to Software Security
Seven practical steps you can begin to take today to secure your applications and prevent the damages a successful cyber-attack can cause.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.