Leaky TLS Certificate Exposes North Korea’s Hangro VPN Infrastructure Across Two Countries
North Korea's Hangro VPN exposed detailed infrastructure across North Korea and Russia via TLS certificates.
North Korea's Hangro VPN platform exposed detailed infrastructure across North Korea and Russia, revealing internal addresses and sensitive network metadata in TLS certificates.
- North Korea's Hangro VPN platform exposed detailed infrastructure across North Korea and Russia.
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | aeoncredit.com.cn | NS hostname observed in a related Chinese assignment Domain aeoncredit.com.cn Passive DNS hostname observed in a related Chinese assignme |
| domain | dns.chinact.net | NS hostname observed in a related Chinese assignment Domain dns.chinact.net Passive DNS hostname observed in a related Chinese assignme |
| domain | futurere.com | arrying a Hangro icon and description of the service Domain futurere.com.kp Historical DPRK-related domain referenced in Hangro infr |
| domain | hangro.net | s):- Type Indicator Description VPN / mail certificate name hangro.net.kp Hangro VPN certificate common name observed on North Kor |
| domain | hero-huishan.cn | NS hostname observed in a related Chinese assignment Domain hero-huishan.cn Passive DNS hostname observed in a related Chinese assignme |
| domain | hero-huishan.com | NS hostname observed in a related Chinese assignment Domain hero-huishan.com Passive DNS hostname observed in a related Chinese assignme |
Full article1,181 words · extracted from cybersecuritynews.com · click to collapse
North Korea’s Hangro platform has exposed an unusually detailed view of infrastructure used to connect officials and trade representatives abroad with systems inside the country.
A newly observed TLS certificate listed servers in North Korea and Russia, along with an internal address that should not have appeared in a public-facing certificate.
Hangro is not malware or a conventional cyberattack tool. It is a state-linked VPN client that also includes email and real-time chat functions, reportedly intended for North Korean personnel outside the country.
Its servers provide a rare technical trail into how overseas users may reach domestic services, unlike the North Korean fake worker campaigns that typically rely on stolen identities and commercial remote-access tools.
Malwarebox identified the exposed certificate data while reviewing a newer management layer deployed around July 2026.
Malwarebox said in a report shared with Cyber Security News (CSN) that the finding links a matching service surface in Pyongyang with hosts in Russia’s Far East, while also revealing older infrastructure in Chinese address space.
The discovery does not prove that the platform has been used in a specific intrusion campaign. It does, however, show that certificate mistakes, weak key handling, and exposed network metadata can reveal sensitive infrastructure even when operators attempt to restrict access through client certificates and unusual network ports.
Leaky TLS Certificate Exposes North Korea’s Hangro VPN Infrastructure
The certificate presented on port 6006 listed five public addresses: three in North Korea and two in Russia. It also included 100.100.100.170, an address from carrier-grade NAT space that is not publicly routable. Publishing it effectively disclosed part of the deployment’s internal addressing plan.
The same management certificate was observed on 175.45.176.21 in Pyongyang and on both Russian systems, 188.43.136.115 and 188.43.136.116.
.webp)
The matching certificate, service exposure, and mutual TLS requirement point to a jointly administered environment, although the report stops short of claiming proof of a central control system.
This type of certificate reuse can be valuable to defenders. As seen in earlier reporting on certificate linked DPRK infrastructure, a reused certificate can allow researchers to group servers that would otherwise appear unrelated and monitor them for changes.
The newer service appears more carefully built than Hangro’s older VPN and mail layer. Port 6006 completed a TLS 1.3 handshake and required a client certificate, while services on ports 465 and 7443 returned a bad-signature error. That failure indicates the older servers did not hold private keys matching the certificates they presented.
Broken Keys and Overseas Access
Researchers found that every signature in Hangro’s 2024 certificate chain failed verification, including the root certificate against itself.
The most likely explanation is that private keys in use do not match the public keys embedded in the certificates, though Malwarebox noted that confirming the cause would require access to the signing environment.
That weakness matters because the Hangro client reportedly trusts certificates installed with the software rather than correctly validating their signature chain.
In practical terms, the platform can continue operating despite a certificate setup that normal browsers, mail clients, and many security products would reject.
The report also revisits a Chinese endpoint configured in Hangro clients, 218.25.43.212. Its network registration named a technical contact using a Silibank email address, and related address assignments were tied to the same record.
.webp)
The evidence supports a DPRK-linked connection in Chinese address space, not ownership of Chinese networks by North Korea.
Organizations monitoring state-linked activity should track the exposed addresses, certificate hashes, unusual TLS ports, and associated domains.
Analysts should also avoid treating a single registry contact as attribution on its own, a restraint that remains important when examining the modular DPRK cyber ecosystem or infrastructure shared with legitimate providers.
For network defenders, the immediate recommendation is to alert on connections to the listed systems, inspect TLS certificates on ports 6006 and 6008, and investigate unexpected traffic involving Hangro-related hostnames.
Certificate transparency, passive DNS, and handshake fingerprinting can help identify new nodes if the operators move or expand the service.
Indicators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| VPN / mail certificate name | hangro.net.kp | Hangro VPN certificate common name observed on North Korean and Russian hosts |
| VPN certificate SHA-256 | b8810eae6ead0ec3a606300c5e3fe9c7af23f836719596e9519f73b4e1e7ad01 | SHA-256 fingerprint of the older Hangro VPN certificate |
| Management TLS fingerprint | 5a2f81451d6c921a7ab845b1856f67d71c76196cc34ace5ef7c7e8e471c3214b | Fingerprint of the TLS certificate served on port 6006 |
| Certificate SHA-256 | 18:16:94:39:C5:45:15:4B:83:64:C3:D8:4E:6A:9D:A8:3B:CE:50:47:43:E4:F9:F3:21:EC:CB:D8:1E:9F:C0:6B | SHA-256 value for the certificate exposed on port 6008 |
| IP address | 175.45.176.21 | North Korean Hangro endpoint and port 6006 management service |
| IP address | 175.45.176.22 | North Korean Hangro endpoint |
| IP address | 175.45.176.32 | North Korean Hangro endpoint |
| IP address | 188.43.136.115 | Russian Hangro endpoint serving management and older services |
| IP address | 188.43.136.116 | Russian Hangro endpoint serving management and older services |
| Internal IP address | 100.100.100.170 | Carrier-grade NAT address exposed in the management certificate SAN |
| IP address | 218.25.43.212 | Default Hangro client target in Chinese address space |
| IP address | 218.25.43.209 | Hangro client TestIP address in the same Chinese network |
| Network range | 218.25.43.208/28 | Chinese range containing the default Hangro endpoint |
| Network range | 218.24.140.88/29 | Chinese network assignment tied to the same registry contact |
| Network range | 218.24.161.240/29 | Chinese network assignment tied to the same registry contact |
| Network range | 218.25.125.144/28 | Chinese network assignment tied to the same registry contact |
| Network range | 218.25.171.88/31 | Chinese network assignment tied to the same registry contact |
| IP range | 61.189.49.233-61.189.49.240 | Chinese assignment tied to the same registry contact |
| Domain | mail.silibank.com | Passive DNS hostname observed at 218.25.43.211, near Hangro’s configured endpoint |
| Domain | silibank.com | Domain associated with the historical registry contact and Hangro distribution paths |
| URL path | silibank.com/fog/update_files/ | Historical location where Hangro installers were reported to have been hosted |
| Domain | ps.ppokkugi.com | Site carrying a Hangro icon and description of the service |
| Domain | futurere.com.kp | Historical DPRK-related domain referenced in Hangro infrastructure research |
| Domain | lnnk.com | Passive DNS hostname observed in a related Chinese assignment |
| Domain | dns.chinact.net | Passive DNS hostname observed in a related Chinese assignment |
| Domain | mail.chinact.net | Passive DNS hostname observed in a related Chinese assignment |
| Domain | mx2.sompo-japanchina.com | Passive DNS hostname observed in a related Chinese assignment |
| Domain | aeoncredit.com.cn | Passive DNS hostname observed in a related Chinese assignment |
| Domain | mall.dssodr.com | Passive DNS hostname observed in a related Chinese assignment |
| Domain | hero-huishan.com | Passive DNS hostname observed in a related Chinese assignment |
| Domain | hero-huishan.cn | Passive DNS hostname observed in a related Chinese assignment |
| Hostname | smtp.star-co.net.kp | DPRK mail relay identified in the broader infrastructure analysis |
| IP address | 175.45.178.56 | Address for smtp.star-co.net.kp |
| Hostname | smtp1.star-co.net.kp | DPRK mail relay identified in the broader infrastructure analysis |
| IP address | 175.45.178.57 | Address for smtp1.star-co.net.kp |
| Hostname | mail.silibank.net.kp | DPRK mail host identified in the broader infrastructure analysis |
| IP address | 175.45.177.33 | Address for mail.silibank.net.kp |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.