Hangro: Investigating North Korean VPN Infrastructure Part 1

2025-01-06 NKInternet

https://nkinternet.wordpress.com/2025/01/06/hangro-north-korean-vpn-infrastructure/

Thumbnail for Hangro: Investigating North Korean VPN Infrastructure Part 1

Hangro is presented as possible North Korean VPN or remote-access infrastructure linked to access into or around the DPRK-controlled network environment. The excerpt identifies four historical Hangro IPs in North Korea and Russia that shared a certificate for hangro.net.kp on port 3225 and also exposed port 8888. Whois data ties hangro.net to Jo Myong Chol, listed as a North Korean national, and to [email protected], an email also associated with other DPRK-affiliated domains. A Hangro software sample reportedly contained a default configuration connecting to 218.25.43.212 on port 8888, while related reporting describes Hangro as a controlled email channel for North Korean trading companies. The infrastructure matters because it suggests DPRK-managed connectivity may rely on external hosting and legacy Silibank-linked administration outside the country’s usual ASN footprint.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN hangro.net 2025-01-06 2025-07-16
IPv4 175.45.176.21 2025-01-06 2025-07-16
IPv4 188.43.136.116 2025-01-06 2025-07-16
IPv4 175.45.176.22 2025-01-06 2025-07-16
IPv4 188.43.136.115 2025-01-06 2025-07-16
DOMAIN hani.star-co.net 2025-01-06 2025-01-06
DOMAIN uriminzogkiri.com 2025-01-06 2025-01-06
IPv4 218.25.43.212 2025-01-06 2025-01-06
IPv4 175.45.176.32 2025-01-06 2025-01-06
DOMAIN ournation-school.com 2014-08-27 2025-01-06
DOMAIN silibank.com 2014-08-27 2025-01-06

Related Reports

« Back