By Lee Tae-hoon
Once again, security experts and government officials have pinpointed North Korea as the perpetrator of a cyber crime, claiming that Pyongyang is responsible for the weeks-long paralysis of Nonghyup, or the National Agricultural Cooperative Federation.
They concluded that the North’s state-run Posts and Telecommunications Corporation was behind denial-of-service (DDoS) attacks against South Korean government and private websites in March this year and in July 2009.
“It seems certain that the same hacker responsible for the past cyber attacks was involved in the latest attack on Nonghyup,” a senior forensic investigator at the Digital Forensic Research Center of Korea University said Sunday.
Asking for anonymity, the digital forensic expert told The Korea Times that investigators have identified a “software birthmark,” a set of unique, inherent characteristics of a hacking tool used in the previous DDoS attacks.
“Nearly three quarters of the codes found in the latest cyber attack are identical to the ones used in the 2009 cyber attack, which paralyzed 21 South Korean websites,” he added.
On Friday, Cheong Wa Dae and ruling party officials revealed that investigative authorities secured circumstantial evidence that points the finger at Pyongyang.
“Investigators have discovered suspicious Internet protocol (IP) addresses of Chinese origins on Nonghyup's servers and a laptop owned by an employee of IBM Korea,” a Cheong Wa Dae official said.
Traces of break-ins have been discovered in the IBM worker’s notebook, which allegedly commanded the deletion of files at the financial institution’s servers on April 12.
Seoul suspects the dubious Chinese IP addresses are the ones lent to the North’s Posts and Telecommunications Corporation and the main source of the Nonghyup attack.
A senior official of the governing Grand National Party has also confirmed that many of the Chinese IP addresses on the April 12 attack match those used in the previous DDoS attacks on Korean websites.
“Investigative authorities have concluded that it was masterminded by a group of hackers with political motives since they did not seek financial gains from the Nonghyup hacking,” the official said.
Experts say it would be impossible for the latest attack to be staged by a different hacker, given that the same IP address used in the 2009 DDoS attack was ascertained out of more than 4.2 billion IP addresses in the world.

지난 2009년 디도스 공격때 처럼 북한이 농협 전산망 마비 사태에 개입됐다는 주장이 제기되고 있다.
수사 당국이 농협을 해킹한 상당 수의 IP와 북한 체신성이 보유한 중국발 IP가 일치하는 점을 밝혀낸 것으로 밝혀졌기 때문이다.
고려대학교 디지털포렌식연구센터 한 관계자에 의하면 수사 당국은 이미 북 소행을 밝힐 수 있는 결정적 증거에 해당하는 소프트웨어 버스마크 (Software Birthmark)를 농협 해킹공격 코드에서 발견했다.
소프트웨어 버스마크는 프로그램을 식별하는데 사용될 수 있는 내재된 고유 특징을 말한다.
그는 2009년 디도스 공격 때 사용된 악성 코드와 이번 공격 때 사용된 소스 코드가 4분에 3이상 일치한다며 동일 인물이 해당 농협 행킹을 주도했을 가능성이 크다고 말했다.
한편 이에 대해 청와대 및 여권의 고위 관계자도 "북한의 소행일 개연성이 상당히 높다”고 밝혔다.
북한의 사이버 테러 공격은 주로 체신청을 통해 이뤄지는 것으로 알려졌다.
지난 2009년 해킹 사건도 북한 체신청이 임대한 중국 IP가 진원지라고 원세훈 국가정보원장이 밝힌 바 있다.