Hangro: Investigating North Korean VPN Infrastructure Part 1
2025-01-06 • NKInternet •
https://nkinternet.wordpress.com/2025/01/06/hangro-north-korean-vpn-infrastructure/
Hangro is presented as possible North Korean VPN or remote-access infrastructure linked to access into or around the DPRK-controlled network environment. The excerpt identifies four historical Hangro IPs in North Korea and Russia that shared a certificate for hangro.net.kp on port 3225 and also exposed port 8888. Whois data ties hangro.net to Jo Myong Chol, listed as a North Korean national, and to [email protected], an email also associated with other DPRK-affiliated domains. A Hangro software sample reportedly contained a default configuration connecting to 218.25.43.212 on port 8888, while related reporting describes Hangro as a controlled email channel for North Korean trading companies. The infrastructure matters because it suggests DPRK-managed connectivity may rely on external hosting and legacy Silibank-linked administration outside the country’s usual ASN footprint.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | hangro.net | 2025-01-06 | 2025-07-16 |
| IPv4 | 175.45.176.21 | 2025-01-06 | 2025-07-16 |
| IPv4 | 188.43.136.116 | 2025-01-06 | 2025-07-16 |
| IPv4 | 175.45.176.22 | 2025-01-06 | 2025-07-16 |
| IPv4 | 188.43.136.115 | 2025-01-06 | 2025-07-16 |
| DOMAIN | hani.star-co.net | 2025-01-06 | 2025-01-06 |
| DOMAIN | uriminzogkiri.com | 2025-01-06 | 2025-01-06 |
| IPv4 | 218.25.43.212 | 2025-01-06 | 2025-01-06 |
| IPv4 | 175.45.176.32 | 2025-01-06 | 2025-01-06 |
| DOMAIN | ournation-school.com | 2014-08-27 | 2025-01-06 |
| DOMAIN | silibank.com | 2014-08-27 | 2025-01-06 |