Now that the cat is out of the bag regarding the use of front companies like BlockNovas LLC

2025-04-25 Team Cymru

https://archive.is/E2Hcp

Thumbnail for Now that the cat is out of the bag regarding the use of front companies like BlockNovas LLC

The archived post ties BlockNovas and related Contagious Interview activity to Russian TransTelecom IP infrastructure previously highlighted in Trend Micro's reporting. The author says the relevant public IPs sit in ranges assigned to InvestStroyTrest, a company that operates ferry service between North Korea and Russia and maintains an office in Rajin. The short source does not add malware analysis, but it provides infrastructure context for DPRK linked front company activity and Russian network ranges observed with DPRK linked operations over several years.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 188.43.33.250 2025-04-23 2025-09-17
DOMAIN blocknovas.com 2025-04-23 2025-04-25
IPv4 188.43.33.251 2025-04-23 2025-04-25

Related Actors

Related Reports

« Back