What We Discovered On a North Korean Server Part 1

2025-06-16 NKInternet

https://nkinternet.wordpress.com/2025/06/16/what-we-discovered-on-a-north-korean-server-part-1/

Thumbnail for What We Discovered On a North Korean Server Part 1

An exposed ownCloud instance at cloud.star.net.kp, resolving to 175.45.176.31, revealed user files and server logs from North Korean-hosted infrastructure. The accessible /data directory exposed files for each user and logs showing activity from RFC-1918 addresses that suggested internal North Korean logins, alongside external access through other ASNs. Failed login attempts reused valid usernames and a shared test user-agent, while some access involved ExpressVPN and VPN Gate infrastructure. The exposure provides rare visibility into DPRK server administration, access patterns, and data-handling failures rather than documenting a conventional intrusion campaign.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN star-co.net 2014-08-27 2026-03-10
DOMAIN silibank.net 2014-08-27 2026-01-27
EMAIL [email protected] 2025-06-16 2025-06-16
EMAIL [email protected] 2025-06-16 2025-06-16
EMAIL [email protected] 2025-06-16 2025-06-16
EMAIL [email protected] 2025-06-16 2025-06-16
DOMAIN cloud.star.net 2025-06-16 2025-06-16
IPv4 175.45.176.31 2025-06-16 2025-06-16

Related Reports

« Back