Exploring the North Korean Email Client: Features and Functionality

2024-09-13 NKInternet

https://nkinternet.wordpress.com/2024/09/13/exploring-the-north-korean-email-client-features-and-functionality/

Thumbnail for Exploring the North Korean Email Client: Features and Functionality

A leaked North Korean email client is shown as a Windows application made up of MailClient.exe, DLLs, and a configuration file, with hashes provided for the main executable and dskinliteud.dll. String analysis indicates use of the Chilkat library and references to protocols including SSH, FTP, SMTP, and TLS, suggesting broader network-capable components beyond basic mail handling. Runtime testing found the client only accepted usernames under the star-co.net.kp domain and exposed a simple offline-oriented workflow with local inbox and outbox areas for storing and sending mail when connectivity is available. The shipped configuration included a North Korean domain entry and a second server profile named 626MailServer pointing to 214.6.26.30, which the author notes is Department of Defense-owned but does not attribute as malicious infrastructure.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN star-co.net 2014-08-27 2026-03-10
HASH 16e8287667a1db5b5645531029d3dfc3 2024-09-13 2024-09-13
HASH e3144b16b70ca666abcafdcef98b0ea9 2024-09-13 2024-09-13
EMAIL [email protected] 2024-09-13 2024-09-13
DOMAIN uieasy.com 2024-09-13 2024-09-13
IPv4 214.6.26.30 2024-09-13 2024-09-13

Related Reports

« Back