Bells Ringing in Dar es Salaam

2025-09-04 Chollima Group

https://chollima-group.io/posts/bells-ringing-in-dar-es-salaam

Thumbnail for Bells Ringing in Dar es Salaam

Chollima Group links the Hailong Jin and Lian Hung personas to suspected North Korean IT worker activity, including GitHub accounts tied to Unity/game development, blockchain work, and overlap with strings seen in Moonstone Sleet's DeTankZone research. Leak data for the goldsea808-linked email is reported to have originated from DPRK IP 45.126.3.252, associated with NetKey/OConnect, while Lian Hung is described as using multiple personas and accessing DPRK-owned Korean-language sites. The investigation pivots from these personas to Bells Inter Trading Limited in Dar es Salaam, Tanzania, where public work permit records identify multiple Korean-named applicants tied to Bells and related entities. Bells-linked Apple apps and connected publisher accounts are associated with VPN and mobile apps totaling more than 12 million installs, suggesting a potentially significant DPRK IT worker commercial footprint beyond commonly tracked regions.

Indicators of Compromise

Type Value First Seen Last Seen
URL https://apkpure.com/guardian-vp… 2025-09-04 2025-09-04
URL https://apkcombo.com/ultraconne… 2025-09-04 2025-09-04
URL https://www.ldplayer.net/games/… 2025-09-04 2025-09-04
URL https://shot-vpn-unlimited-free… 2025-09-04 2025-09-04
DOMAIN global808.wixsite.com 2025-09-04 2025-09-04
DOMAIN apkcombo.com 2025-09-04 2025-09-04
DOMAIN marogus211.wixsite.com 2025-09-04 2025-09-04
DOMAIN shot-vpn-unlimited-free-vpn-pro… 2025-09-04 2025-09-04
IPv4 69.30.210.152 2025-09-04 2025-09-04
IPv4 69.30.210.159 2025-09-04 2025-09-04
IPv4 107.150.47.23 2025-09-04 2025-09-04
IPv4 173.208.245.144 2025-09-04 2025-09-04
IPv4 173.208.245.151 2025-09-04 2025-09-04
IPv4 107.150.47.16 2025-09-04 2025-09-04
IPv4 102.215.28.11 2025-09-04 2025-09-04
IPv4 45.126.3.252 2025-08-25 2025-09-04

Related Actors

Related Reports

« Back