'JustJoin' Landing Page Linked to Suspected DPRK Activity Resurfaces

2025-01-14 Hunt.io

https://hunt.io/blog/justjoin-landing-page-linked-to-suspected-dprk-activity-resurfaces

Thumbnail for 'JustJoin' Landing Page Linked to Suspected DPRK Activity Resurfaces

Hunt identified a Hostwinds server at 23.254.167[.]216 hosting a resurfaced "JustJoin" landing page, a theme previously linked in public reporting to TA444 or BlueNoroff activity. The cluster includes domains such as make-hex-32332e3235342e3136372e323136-rr.1u[.]ms and a0info.v6[.]army, with the hex-encoded domain resolving back to the same IP address. Two additional Hostwinds servers share the same SSH fingerprint, suggesting coordinated infrastructure management, and one exposes mail-related services that could support phishing. The report advises defenders to watch for domains impersonating meeting, fintech, or cryptocurrency services and to pivot on HTML hashes, IPs, domains, and shared SSH keys.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 23.254.167.216 2025-01-14 2026-04-17
HASH e1f6b7f621a391a9d26e9a196974f3e… 2025-01-14 2026-04-01
IPv4 108.174.194.196 2025-01-14 2026-04-01
IPv4 108.174.194.44 2025-01-14 2026-04-01
DOMAIN taglala.com 2025-01-14 2025-01-14

Related Actors

Related Reports

« Back