What We Discovered On a North Korean Server Part 1
2025-06-16 • NKInternet •
https://nkinternet.wordpress.com/2025/06/16/what-we-discovered-on-a-north-korean-server-part-1/
An exposed ownCloud instance at cloud.star.net.kp, resolving to 175.45.176.31, revealed user files and server logs from North Korean-hosted infrastructure. The accessible /data directory exposed files for each user and logs showing activity from RFC-1918 addresses that suggested internal North Korean logins, alongside external access through other ASNs. Failed login attempts reused valid usernames and a shared test user-agent, while some access involved ExpressVPN and VPN Gate infrastructure. The exposure provides rare visibility into DPRK server administration, access patterns, and data-handling failures rather than documenting a conventional intrusion campaign.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | star-co.net | 2014-08-27 | 2026-03-10 |
| DOMAIN | silibank.net | 2014-08-27 | 2026-01-27 |
| [email protected] | 2025-06-16 | 2025-06-16 | |
| [email protected] | 2025-06-16 | 2025-06-16 | |
| [email protected] | 2025-06-16 | 2025-06-16 | |
| [email protected] | 2025-06-16 | 2025-06-16 | |
| DOMAIN | cloud.star.net | 2025-06-16 | 2025-06-16 |
| IPv4 | 175.45.176.31 | 2025-06-16 | 2025-06-16 |