North Korea's Hangro VPN Certificates Expose Internal CGNAT Address and Russia-Linked Infrastructure
New Hangro VPN certificates tie three North Korean and two Russian Far East servers to a shared management PKI, exposing an internal carrier-grade NAT address.
DPRK-linked Hangro VPN and mail platform deployed a new certificate hierarchy in July 2026 on TCP port 6006, issued by an internal root named "KEVIN ROOT CA" (RSA-4096, SHA-256, valid 2026-2036) and presented from three North Korean and two Russian IP addresses. The certificate's SAN enumerates all five public-facing Hangro systems plus 100.100.100.170, an address in the RFC 6598 carrier-grade NAT range, indicating an internal management reference. The Russian endpoints sit in TransTeleCom's Far East network in Khabarovsk, and the shared certificate fingerprint across Pyongyang and Russian hosts suggests the infrastructure is administered as a single environment. The software is derived from SoftEther VPN with mutual TLS, contrasting with a cryptographically flawed 2024 certificate chain (HBS2024) that exhibited signature handshake failures; historic client callbacks had pointed to China Unicom address space linked to Silibank. Both outlets report the exposure of Hangro infrastructure spanning North Korea and Russia; Cyber Security News corroborates the story without adding conflicting details.
- New certificate hierarchy deployed in July 2026 on TCP port 6006
- Root CA named "KEVIN ROOT CA" using RSA-4096 and SHA-256, valid 2026-2036
- Certificate presented from three North Korean and two Russian IP addresses
- SAN lists all five public-facing Hangro systems plus internal CGNAT address 100.100.100.170 (RFC 6598 range)
- Russian endpoints located in TransTeleCom's Far East network in Khabarovsk
- Same certificate fingerprint shared across Pyongyang and Russian systems, indicating one administrative environment
- VPN software derived from SoftEther VPN with mutual TLS
- Legacy 2024 HBS2024 certificate chain was cryptographically flawed with signature handshake failures
Coverage timelineoldest first · each row is one article
- · 6d agoNorth Korea’s Hangro VPN Certificate Exposes Internal Network and Russia-Linked Infrastructure
GBHackers· 32
New Hangro VPN certificates tie North Korean and Russian Far East servers to a shared management PKI, exposing an internal carrier-grade NAT address.
- · 5d agoLeaky TLS Certificate Exposes North Korea’s Hangro VPN Infrastructure Across Two Countries
Cyber Security News· 90
North Korea's Hangro VPN exposed detailed infrastructure across North Korea and Russia via TLS certificates.