North Korea’s Hangro VPN Certificate Exposes Internal Network and Russia-Linked Infrastructure
New Hangro VPN certificates tie North Korean and Russian Far East servers to a shared management PKI, exposing an internal carrier-grade NAT address.
DPRK-linked Hangro VPN and mail platform deployed a new certificate hierarchy in July 2026 on TCP port 6006, issued by an internal root named "KEVIN ROOT CA" (RSA-4096, SHA-256, valid 2026-2036) and presented from three North Korean and two Russian IP addresses. The certificate's SAN enumerates all five public-facing Hangro systems plus 100.100.100.170, an address in the RFC 6598 carrier-grade NAT range, indicating an internal management reference. The Russian endpoints sit in TransTeleCom's Far East network in Khabarovsk, and the shared fingerprint across Pyongyang and Russian hosts suggests administration as one environment. The software is derived from SoftEther VPN with mutual TLS, and contrasts with a cryptographically flawed 2024 certificate chain that showed handshake failures.
- SAN lists public servers plus CGNAT address 100.100.100.170
- Same certificate fingerprint on Pyongyang and Russian systems
- Russian IPs in TransTeleCom's Khabarovsk Far East range
- Legacy 2024 HBS2024 chain had signature handshake failures
- Historic client callbacks pointed to China Unicom space linked to Silibank
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| ipv4 | 175.45.176.21 | is presented from Hangro-linked IP addresses in North Korea 175.45.176.21, 175.45.176.22 and 175.45.176.32 and two Russian systems, 1 |
| ipv4 | 175.45.176.22 | om Hangro-linked IP addresses in North Korea 175.45.176.21, 175.45.176.22 and 175.45.176.32 and two Russian systems, 188.43.136.115 a |
| ipv4 | 175.45.176.32 | P addresses in North Korea 175.45.176.21, 175.45.176.22 and 175.45.176.32 and two Russian systems, 188.43.136.115 and 188.43.136.116. |
| ipv4 | 188.43.136.115 | 1, 175.45.176.22 and 175.45.176.32 and two Russian systems, 188.43.136.115 and 188.43.136.116. It is valid from July 26, 2026, through |
| ipv4 | 218.25.43.212 | rarchy. Hangro’s historical client configuration pointed to 218.25.43.212 on port 8888, an address in China Unicom space in Liaoning. |
Full article817 words · extracted from gbhackers.com · click to collapse
North Korea’s Hangro VPN and mail platform has deployed a new certificate hierarchy that exposes an apparent cross-border management environment spanning systems in Pyongyang and Russia’s Far East.
The certificate’s Subject Alternative Name field lists the platform’s publicly exposed servers alongside a carrier-grade NAT address, offering an unusual glimpse into how the service may be addressed internally.
The new infrastructure surfaced around July 2026 on TCP port 6006, operating alongside Hangro’s older, technically flawed 2024 certificate chain.
Earlier reporting found the software is derived from SoftEther VPN and uses mutual TLS for client authentication.
The management certificate is presented from Hangro-linked IP addresses in North Korea 175.45.176.21, 175.45.176.22 and 175.45.176.32 and two Russian systems, 188.43.136.115 and 188.43.136.116.
It is valid from July 26, 2026, through July 23, 2036, uses RSA-4096 with SHA-256, and is issued by an internal root named “KEVIN ROOT CA.”
Most significantly, its SAN inventory enumerates all five public-facing Hangro systems as well as 100.100.100.170.
That final address falls within 100.64.0.0/10, the carrier-grade NAT range reserved by RFC 6598 and not globally routable on the public Internet.
Its inclusion in a public-facing certificate likely exposes an internal addressing reference or management endpoint that was not intended for external visibility.
The same certificate fingerprint and service behavior appear across the Pyongyang and Russian systems, indicating that the servers are likely operated through a shared administrative model.
However, the evidence does not establish a proven centralized control plane: port 6006 completes TLS 1.3 negotiation but then requires a client certificate, preventing unauthenticated access to the application layer.
The 2026 certificate family contrasts sharply with Hangro’s previously observed 2024 hierarchy.
The earlier deployment used an EC P-384 chain rooted in HBS2024, with hrra2024 issuing certificates for the VPN endpoint, SMTP service and IMAP/POP service.
Research into the older service showed certificate-related handshake failures on Hangro’s VPN and mail ports, including tls_process_key_exchange: bad signature.

The behavior suggested that the deployed private keys did not match the public keys embedded in the certificates, or that the chain was otherwise cryptographically inconsistent.
Synaptic Researchers said that, Hangro is a DPRK-linked client combining VPN access, email and real-time chat functions, reportedly intended for North Korean representatives and organizations operating outside the country.
Hangro VPN Exposure
Port 6006 does not show the same failure. It completes certificate verification successfully with TLS 1.3, negotiates TLS_AES_256_GCM_SHA384, and requests client authentication.
That difference suggests Hangro’s operators introduced a separate and more functional management PKI while leaving the legacy VPN access and mail certificate environment in place.
Silibanks known user base was substantially Japanese, its 2001 website carried a dedicated Japanese section and two Japanese corporations appear in these blocks.
The Russian endpoints sit in 188.43.136.0/24, a range associated with TransTeleCom’s Far East network in Khabarovsk.

This placement is operationally notable because Hangro has long exposed mirrored infrastructure from North Korean and Russian address space.
The service was previously documented on the same Russian IPs and on North Korean hosts sharing Hangro certificates.
The new port 6006 certificate therefore strengthens the case that the Russian systems are not merely passive relays.
Port 81 is the exception. Behind the same proxy sits a JBoss Web instance serving nothing but its default welcome page, Last-Modified: Tue, 10 Jan 2017 05:07:28 GMT.
They expose an identical management-facing service, use the same credentials and enumerate the same cross-border network inventory.

A second certificate exposed only on TCP/6008 across the two Russian hosts appears materially less mature.
It contains placeholder-style “kevin” identity fields, lacks modern X.509 extensions, and does not appear on the Pyongyang servers.
This may represent an earlier Russian-side deployment or a separate component that predated the newer management hierarchy.
Hangro’s historical client configuration pointed to 218.25.43.212 on port 8888, an address in China Unicom space in Liaoning.
Earlier investigation linked the allocation to an APNIC contact using a silibank.com email address, connecting the network trail to the DPRK-associated Silibank service.
That Chinese endpoint should not, however, be treated as part of the current certificate-bound management environment.
The new “KEVIN” certificate family has only been observed on the North Korean and Russian systems, while the older Chinese Hangro callback infrastructure appears distinct and largely inactive.
The evidence points to a layered architecture: legacy China-based infrastructure associated with client distribution and historic connectivity, and a newer operational layer linking Pyongyang with Russian-hosted systems.
The shared 2026 management certificate is the strongest public indicator yet that Hangro’s cross-border infrastructure is administered as one environment rather than as isolated regional nodes.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.