North Korean army suspected over cyberattacks

Published: Saturday, July 11, 2009 10:39 a.m. MDT
 |  E-MAIL | PRINT | FONT + - 

SEOUL, South Korea — A North Korean army lab of hackers was ordered to "destroy" South Korean communications networks — evidence the isolated regime was behind cyberattacks that paralyzed South Korean and American Web sites — news reports said Saturday, citing an intelligence briefing.

Members of the parliamentary intelligence committee have said in recent days that the National Intelligence Service has also pointed to a North Korean boast last month that it was "fully ready for any form of high-tech war."

The spy agency told lawmakers Friday that a research institute affiliated with the North's Ministry of People's Armed Forces received an order to "destroy the South Korean puppet communications networks in an instant," the mass-circulation JoongAng Ilbo newspaper reported.

The paper, citing unidentified members of parliament's intelligence committee, said the institute, known as Lab 110, specializes in hacking and spreading malicious programs.

The Ministry of People's Armed Forces is the secretive nation's defense ministry.

The NIS — South Korea's main spy agency — said it couldn't confirm the report. Calls to several key intelligence committee members went unanswered Saturday.

The agency, however, issued a statement late Saturday saying it has "various evidence" of North Korean involvement, though has yet to reach a conclusion.

Story continues below

South Korea's Yonhap news agency carried a similar report, saying the NIS obtained a North Korean document issuing the June 7 order. The report, quoting an unidentified senior ruling party official, said the North Korean institute is affiliated with the North Korean People's Army.

The state-run Korea Communications Commission said Friday that it had identified and blocked five Internet Protocol, or IP, addresses in five countries used to distribute computer viruses that caused the wave of Web site outages, which began in the U.S. on July 4.

The addresses point to the computers that distributed the virus that triggered so-called denial of service attacks in which floods of computers try to connect to a single site at the same time, overwhelming the server.

They were in Austria, Georgia, Germany, South Korea and the U.S., a commission official said. He spoke on condition of anonymity because he is not authorized to speak to the media on the record.

Speculation over who was responsible for the attacks that targeted high-profile Web sites, including those of the White House and South Korea's presidential Blue House, has centered on North Korea.

And though such finger-pointing has been trickling out since the attacks began, the identity of the IP addresses themselves provides little in the way of clarity.

Recent comments

Welcome to the new battlefield where technology becomes the method of...

Tab L. Uno | July 11, 2009 at 11:09 a.m.

previousnext

Latest comments

Obama: More troops with deadline

Yepper's, you betcha, (as Sarah Palin would say), the same DNA is running in...

Wouldn't you think the victim would have been killed INSIDE the home if he...

Max Hall: a fixture in rivalry lore

The bottom line is no matter how much you don't like the other team you don't...

Letters: Hatred is uncalled for

I HATE THE U | 12:02 p.m. You all have similar stories because they are...

This is a really cool story, thanks for writing it 7 congrats to the family.

MWC '09 season in review

No matter what the cougs do - they will be linked to the Vegas bowl - enjoy...

JT is an excellent player and I hate when people bag on him. Yes, he has poor...

6 sons soar as Eagle Scouts

What does scouting actually have to do with being awesome?... Answer:...

Letters: Left-wing AP

'And your last sad attempt, the James Early Ray "quote" is simply a lie.' -...

"One thing you can't hide, is when you're crippled inside." John Lennon.

Advertisements