The machines stopped at two in the afternoon. On 20 March 2013, at 14:00 Korea Standard Time, computers inside three broadcasters — KBS, MBC and YTN — and three financial institutions — Nonghyup, Shinhan Bank and Jeju Bank — began writing over their own disks. LG U+, an internet provider whose own network was hit the same afternoon, found its page replaced by three skull drawings on a black screen above the words "hacked by Whois Team". The broadcasts themselves stayed on air; it was the newsroom computers that went dark. Shinhan's internet banking and cash machines were out for roughly two hours. By late the following morning every affected bank except Nonghyup had restored service, and some Nonghyup branches were still paralysed; full recovery across the six organisations took days. Counts given at the time ranged from about 32,000 machines to close to 50,000.
The delivery route was the thing built to be trusted. AhnLab, whose patch management software was in use at some targeted sites, said attackers had taken legitimate administrator credentials for patch servers and pushed the malware out the way an update goes out; no flaw in its product was involved. Dell SecureWorks found three variants writing repeating strings across the master boot record and on through the drive: PRINCPES and PRINCIPES in one, HASTATI. in another, PR!NCPES in a third, the front and second lines of a Roman legion. One variant slept, waking to check the clock, until 20 March 2013 at 1400. It took removable drives too, and harvested SSH credentials stored by mRemote and SecureCRT to push a shell script onto Unix machines and delete partitions.
The attribution went wrong in public. Investigators traced malicious files created on Nonghyup's update server to an address, 101.106.25.105, which they placed in China; the finding ran round the world within hours and fitted a widely held view that Pyongyang routes operations through Chinese networks. On 22 March the Korea Communications Commission said the address was, on closer analysis, not Chinese at all but a private one inside the infected bank's own network. Seoul then waited three weeks. On 10 April a government investigation team said the evidence — malware families and the routes into the networks, some using addresses seen since 2009 — pointed to North Korea. On 13 April the General Staff of the Korean People's Army denied involvement through the Korean Central News Agency.
Researchers spent the rest of the year working backwards. In July McAfee published on what it called Operation Troy, describing March as the visible end of a campaign collecting South Korean and American military material since 2009; Symantec, tracking the same activity under the name DarkSeoul, put four years of intrusions down to a single group, adding that this held whether or not the gang worked for North Korea. On 16 July the Ministry of Science, ICT and Future Planning said the malware used against government sites on 25 June was a variant of the code of 20 March and that the addresses matched Pyongyang's earlier attempts; a senior ministry official, Park Jae-moon, told reporters that "North Korea is believed to be behind the attack". What had changed was the object. The theft was the preparation; the damage was the point.
The flood and the headline
The traffic began on 18 March 2013 at roughly ten gigabits a second against the website of Spamhaus, the anti-spam organisation whose blocklists mail providers use, and reached about ninety the next day. Spamhaus went to CloudFlare and the attackers followed, peaking, by CloudFlare's account, at 120 gigabits a second against its network on 22 March, with one tier-one provider telling CloudFlare it had seen more than 300 further upstream — the figure the whole story was later built on, and CloudFlare's alone. The method was reflection: spoofed queries bounced off some of the 21.7 million misconfigured open resolvers CloudFlare counted, each answer far larger than the question. CloudFlare's post of 27 March was headed "The DDoS That Almost Broke the Internet". The engineers who could see the traffic disagreed at once. Renesys said the internet as a whole had seen no widespread disruption, whatever local service had been degraded, and its chief technology officer, James Cowie, said fears for the European exchanges had "proven unfounded". Sven Olaf Kamphuis was arrested in Spain in April 2013 and convicted at Dordrecht on 14 November 2016; he denied involvement throughout and served no further time.
The file on the first lady
On 2 March 2013 Evernote reset the passwords of about fifty million users after finding suspicious activity on its network. Usernames, email addresses and password data had been reached, the company said; the passwords were hashed and salted, there was no evidence that stored content had been accessed, changed or lost, and no indication that payment information had been touched. Eleven days later Brian Krebs wrote about credit reports sold cheaply in criminal forums, and about a site, exposed.su, that had been posting the social security numbers, addresses and credit files of public figures — the first lady, the vice-president, the director of the FBI, actors. The following afternoon his own site went down under a denial of service attack, his mitigation provider received a forged letter purporting to come from the FBI, and armed police arrived at his door: a caller claiming to be him had told the emergency line that Russians had broken in and shot his wife — placed, Krebs corrected afterwards, not by spoofing his mobile number as first believed but through a text relay service for deaf callers. He was handcuffed on his own step. Mir Islam was sentenced on 11 July 2016 to twenty-four months.
Named at both ends
India spent the month accused in two directions. In the second week of March 2013 the Mumbai daily DNA reported that officials of the National Technical Research Organisation, working with private specialists, had found a file called "army cyber policy" attached to compromised email accounts of senior scientists at the Defence Research and Development Organisation, and that thousands of documents — papers of the Cabinet Committee on Security among them — had been uploaded to a server in Guangdong province in China. The defence minister, A.K. Antony, said only that "Intelligence agencies are investigating the matter at this stage and I do not want to say anything else", and asked the defence secretary, Shashi Kant Sharma, for a report. DRDO's spokesman, Ravi Gupta, said that "no incidence of breach of security of DRDO's computers has come to notice". No finding was ever published.
The other direction pointed outward. On 17 March a Norwegian newspaper reported that Telenor had gone to the police over an unlawful intrusion; senior managers had been sent documents exploiting a Windows flaw Microsoft had patched in April 2012. NorCERT passed details to the security firm Norman, which followed the infrastructure for two months and, on 20 May 2013, published a report placing the registration and addresses behind it in India, with targets concentrated in Pakistan and activity running back to at least 2010. Its researcher, Snorre Fagerland, said there was no direct evidence of state sponsorship, but that the possibility could not be dismissed. New Delhi did not respond publicly, and had no obligation to: the duty to report an incident came by direction in 2022, the statute in 2023.
Hinton's three-man company goes to Google
On 12 March 2013 Google bought DNNresearch, a company with no product and three employees: Geoffrey Hinton and his graduate students Alex Krizhevsky and Ilya Sutskever, incorporated the year before inside the University of Toronto's computer science department on the strength of Krizhevsky's image classifier of the previous autumn. Google did not say what it paid. Krizhevsky and Sutskever moved to Google; Hinton divided his time between the university and Google's offices in Toronto and Mountain View. Thirteen days later Yahoo bought Summly, a news summarisation app written by a seventeen-year-old Londoner, Nick D'Aloisio, on technology licensed from SRI International; that price was not officially disclosed either, the app was closed and the work folded into Yahoo's mobile products. Nvidia used its developer conference in San Jose on 19 March to set out a roadmap naming a future architecture, Volta, built around stacked memory; it reached customers in 2017. Sutskever left Google in 2015 to co-found OpenAI, and Hinton resigned in May 2023 to speak freely about the risks.
Java patched, then broken three times
Oracle broke its quarterly schedule in the first week of March 2013 to push out Java SE 7u17 and 6u43 against CVE-2013-1493, a flaw in the runtime's colour management code that FireEye had found in use since late February to drop a remote access tool it called McRAT; the scheduled update was six weeks off. Days later, at CanSecWest in Vancouver, Pwn2Own paid for exploits against every browser entered — Nils and Jon Butler of MWR Labs took Chrome for $100,000 — and Java was broken three times on the first day. Java, the French firm VUPEN said, was "really easy because there's no sandbox"; Oracle deprecated the browser plug-in in 2016 and dropped it from the platform in 2018. On 20 March CrySyS Lab and Hungary's national security authority described a campaign that patched TeamViewer in memory to remove the signs it was running; Kaspersky Lab, the same day, called it TeamSpy and traced it back close to a decade. The thread through the month was software the machine already trusted: a runtime, a plug-in, a remote support tool.
⏳ Time capsule — March 2013
- On 13 March the conclave in Rome elected Jorge Mario Bergoglio, archbishop of Buenos Aires, on the fifth ballot; white smoke rose at 19:06 local time and he took the name Francis.
- On 14 March the first session of the 12th National People's Congress in Beijing elected Xi Jinping president of the People's Republic of China.
- On 18 March Cyprus closed its banks against a run; the European Central Bank said on 21 March it would end emergency lending to Cypriot banks on the 25th, and a rescue was agreed that day, protecting deposits below €100,000 and taking the loss from the uninsured balances above it.
- On 19 March the Lok Sabha and on 21 March the Rajya Sabha passed the Criminal Law (Amendment) Bill, which received assent on 2 April 2013 and was deemed in force from 3 February.
The damage was the point
March 2013 turned out to be an early chapter of a much longer story. In 2016 a coalition of security companies led by Novetta worked through shared code and tied the group behind DarkSeoul to the intrusion at Sony Pictures in November 2014; the same lineage runs on through the ransomware worm of May 2017, and in September 2018 the United States charged a North Korean programmer, Park Jin Hyok, over that run of operations. The technique did not stay rare either. A wiper pushed through a trusted update channel and timed to fire at once across an organisation is now a category with a name and its own defences, and the old assumption that an intruder wants to stay quiet and keep stealing no longer holds on its own.
Two smaller lessons of the month aged better than the headlines did. The address Seoul first placed in China was a private one on the victim's own network, and the correction never travelled as far as the error — a pattern repeated in every attribution rush since. And the flood against Spamhaus did not break the internet: the operators who could see the traffic said so within a day, the record was broken repeatedly in the years that followed, and open DNS resolvers were still being closed long afterwards. In India nothing from that month was ever officially settled. No finding from the DRDO inquiry was published and no answer was made to the Norman report, and the obligations that would have forced disclosure arrived nearly a decade later.