What makes you tell it looks like DNS poisoning? It if were DNS poisoning, some resolvers would have been poisoned but not all, while, here, everybody saw the attacker's IP address. http://www.bortzmeyer.org/observations-wikileaks.html
Since it is a ccTLD, it is a nepalese internal matter and I don't see why ICANN should be involved at all. Ask local authorities, write to the governement, raise the issue in the local Internet community, etc.