Bells Ringing in Dar es Salaam
2025-09-04 • Chollima Group •
https://chollima-group.io/posts/bells-ringing-in-dar-es-salaam
Chollima Group links the Hailong Jin and Lian Hung personas to suspected North Korean IT worker activity, including GitHub accounts tied to Unity/game development, blockchain work, and overlap with strings seen in Moonstone Sleet's DeTankZone research. Leak data for the goldsea808-linked email is reported to have originated from DPRK IP 45.126.3.252, associated with NetKey/OConnect, while Lian Hung is described as using multiple personas and accessing DPRK-owned Korean-language sites. The investigation pivots from these personas to Bells Inter Trading Limited in Dar es Salaam, Tanzania, where public work permit records identify multiple Korean-named applicants tied to Bells and related entities. Bells-linked Apple apps and connected publisher accounts are associated with VPN and mobile apps totaling more than 12 million installs, suggesting a potentially significant DPRK IT worker commercial footprint beyond commonly tracked regions.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | https://apkpure.com/guardian-vp… | 2025-09-04 | 2025-09-04 |
| URL | https://apkcombo.com/ultraconne… | 2025-09-04 | 2025-09-04 |
| URL | https://www.ldplayer.net/games/… | 2025-09-04 | 2025-09-04 |
| URL | https://shot-vpn-unlimited-free… | 2025-09-04 | 2025-09-04 |
| DOMAIN | global808.wixsite.com | 2025-09-04 | 2025-09-04 |
| DOMAIN | apkcombo.com | 2025-09-04 | 2025-09-04 |
| DOMAIN | marogus211.wixsite.com | 2025-09-04 | 2025-09-04 |
| DOMAIN | shot-vpn-unlimited-free-vpn-pro… | 2025-09-04 | 2025-09-04 |
| IPv4 | 69.30.210.152 | 2025-09-04 | 2025-09-04 |
| IPv4 | 69.30.210.159 | 2025-09-04 | 2025-09-04 |
| IPv4 | 107.150.47.23 | 2025-09-04 | 2025-09-04 |
| IPv4 | 173.208.245.144 | 2025-09-04 | 2025-09-04 |
| IPv4 | 173.208.245.151 | 2025-09-04 | 2025-09-04 |
| IPv4 | 107.150.47.16 | 2025-09-04 | 2025-09-04 |
| IPv4 | 102.215.28.11 | 2025-09-04 | 2025-09-04 |
| IPv4 | 45.126.3.252 | 2025-08-25 | 2025-09-04 |