Exploring the North Korean Email Client: Features and Functionality
2024-09-13 • NKInternet •
A leaked North Korean email client is shown as a Windows application made up of MailClient.exe, DLLs, and a configuration file, with hashes provided for the main executable and dskinliteud.dll. String analysis indicates use of the Chilkat library and references to protocols including SSH, FTP, SMTP, and TLS, suggesting broader network-capable components beyond basic mail handling. Runtime testing found the client only accepted usernames under the star-co.net.kp domain and exposed a simple offline-oriented workflow with local inbox and outbox areas for storing and sending mail when connectivity is available. The shipped configuration included a North Korean domain entry and a second server profile named 626MailServer pointing to 214.6.26.30, which the author notes is Department of Defense-owned but does not attribute as malicious infrastructure.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | star-co.net | 2014-08-27 | 2026-03-10 |
| HASH | 16e8287667a1db5b5645531029d3dfc3 | 2024-09-13 | 2024-09-13 |
| HASH | e3144b16b70ca666abcafdcef98b0ea9 | 2024-09-13 | 2024-09-13 |
| [email protected] | 2024-09-13 | 2024-09-13 | |
| DOMAIN | uieasy.com | 2024-09-13 | 2024-09-13 |
| IPv4 | 214.6.26.30 | 2024-09-13 | 2024-09-13 |