'JustJoin' Landing Page Linked to Suspected DPRK Activity Resurfaces
2025-01-14 • Hunt.io •
https://hunt.io/blog/justjoin-landing-page-linked-to-suspected-dprk-activity-resurfaces
Hunt identified a Hostwinds server at 23.254.167[.]216 hosting a resurfaced "JustJoin" landing page, a theme previously linked in public reporting to TA444 or BlueNoroff activity. The cluster includes domains such as make-hex-32332e3235342e3136372e323136-rr.1u[.]ms and a0info.v6[.]army, with the hex-encoded domain resolving back to the same IP address. Two additional Hostwinds servers share the same SSH fingerprint, suggesting coordinated infrastructure management, and one exposes mail-related services that could support phishing. The report advises defenders to watch for domains impersonating meeting, fintech, or cryptocurrency services and to pivot on HTML hashes, IPs, domains, and shared SSH keys.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 23.254.167.216 | 2025-01-14 | 2026-04-17 |
| HASH | e1f6b7f621a391a9d26e9a196974f3e… | 2025-01-14 | 2026-04-01 |
| IPv4 | 108.174.194.196 | 2025-01-14 | 2026-04-01 |
| IPv4 | 108.174.194.44 | 2025-01-14 | 2026-04-01 |
| DOMAIN | taglala.com | 2025-01-14 | 2025-01-14 |