North Korea's Hangro Revisited
This analysis details updates to Hangro, North Korea's state VPN and mail system infrastructure, spanning North Korean, Russian, and Chinese network address spaces. The service uses a certificate hierarchy with cryptographic anomalies and supports bulk mail transfers over intermittent connections. The infrastructure has evolved from a commercial email gateway to a certificate-bound VPN service for trade representatives. Network assignments linked to Silibank and infrastructure in the Russian Far East have been identified. The system employs large message limits and ETRN capabilities for mail relay.
AI Analysis
Technical Summary
Hangro is a North Korean state-operated VPN and mail product with infrastructure distributed across North Korean, Russian, and Chinese IP address spaces. A new certificate hierarchy deployed in July 2026 shows cryptographic anomalies where signatures fail verification, differing from the 2024 version. The infrastructure includes six network assignments in Chinese address space linked to Silibank and networks in the Russian Far East designated KPOST. Originally a commercial email gateway from 2001, Hangro evolved into a certificate-bound VPN issued to trade representatives via consulates. The mail system is configured for bulk transfers over intermittent connections, supporting ten gigabyte message limits and ETRN capabilities.
Potential Impact
The presence of cryptographic anomalies in the certificate hierarchy may undermine the integrity and trustworthiness of the VPN and mail system. The cross-border infrastructure spanning North Korea, Russia, and China facilitates state-controlled communications and bulk mail transfers, potentially supporting covert or resilient communication channels. The use of large message limits and ETRN capabilities indicates an ability to transfer significant volumes of data despite intermittent connectivity. However, no known exploits in the wild have been reported.
Mitigation Recommendations
No specific remediation or patch information is available. As this is a state-operated infrastructure with no vendor advisory or patch status, standard mitigation recommendations do not apply. Monitoring and defensive measures should focus on detection and network-level controls where possible.
Indicators of Compromise
- domain: mail.silibank.net.kp
- domain: smtp.star-co.net.kp
- domain: mail.silibank.com
- ip: 175.45.176.21
- ip: 175.45.178.57
- ip: 175.45.178.56
- ip: 175.45.177.33
- ip: 175.45.176.22
- ip: 175.45.176.32
- ip: 188.43.136.115
- ip: 188.43.136.116
- domain: hangro.net.kp
- ip: 218.25.43.212
- domain: silibank.com
- hash: b8810eae6ead0ec3a606300c5e3fe9c7af23f836719596e9519f73b4e1e7ad01
- hash: 5a2f81451d6c921a7ab845b1856f67d71c76196cc34ace5ef7c7e8e471c3214b
- domain: ps.ppokkugi.com
- domain: futurere.com.kp
- domain: lnnk.com
- domain: dns.chinact.net
- domain: mail.chinact.net
- domain: mx2.sompo-japanchina.com
- domain: aeoncredit.com.cn
- domain: mall.dssodr.com
- domain: hero-huishan.com
- domain: hero-huishan.cn
- domain: smtp1.star-co.net.kp
- ip: 218.24.140.88
- ip: 218.24.140.94
- ip: 218.24.140.95
- ip: 218.24.161.240
- ip: 218.24.161.247
- ip: 218.25.125.144
- ip: 218.25.125.150
- ip: 218.25.125.158
- ip: 218.25.125.159
- ip: 218.25.171.88
- ip: 218.25.171.89
- ip: 218.25.43.208
- ip: 218.25.43.211
- ip: 218.25.43.223
- ip: 61.189.49.233
- ip: 61.189.49.234
- ip: 61.189.49.240
- url: http://silibank.com/fog/update_files/
- domain: kevin.com
- domain: nkinternet.com
North Korea's Hangro Revisited
Description
This analysis details updates to Hangro, North Korea's state VPN and mail system infrastructure, spanning North Korean, Russian, and Chinese network address spaces. The service uses a certificate hierarchy with cryptographic anomalies and supports bulk mail transfers over intermittent connections. The infrastructure has evolved from a commercial email gateway to a certificate-bound VPN service for trade representatives. Network assignments linked to Silibank and infrastructure in the Russian Far East have been identified. The system employs large message limits and ETRN capabilities for mail relay.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Hangro is a North Korean state-operated VPN and mail product with infrastructure distributed across North Korean, Russian, and Chinese IP address spaces. A new certificate hierarchy deployed in July 2026 shows cryptographic anomalies where signatures fail verification, differing from the 2024 version. The infrastructure includes six network assignments in Chinese address space linked to Silibank and networks in the Russian Far East designated KPOST. Originally a commercial email gateway from 2001, Hangro evolved into a certificate-bound VPN issued to trade representatives via consulates. The mail system is configured for bulk transfers over intermittent connections, supporting ten gigabyte message limits and ETRN capabilities.
Potential Impact
The presence of cryptographic anomalies in the certificate hierarchy may undermine the integrity and trustworthiness of the VPN and mail system. The cross-border infrastructure spanning North Korea, Russia, and China facilitates state-controlled communications and bulk mail transfers, potentially supporting covert or resilient communication channels. The use of large message limits and ETRN capabilities indicates an ability to transfer significant volumes of data despite intermittent connectivity. However, no known exploits in the wild have been reported.
Defensive Guidance
No specific remediation or patch information is available. As this is a state-operated infrastructure with no vendor advisory or patch status, standard mitigation recommendations do not apply. Monitoring and defensive measures should focus on detection and network-level controls where possible.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://blog.synapticsystems.de/north-koreas-hangro-revisited"]
- Pulse Id
- 6ab15e0fe200afb0f82b8895
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domainmail.silibank.net.kp | — | |
domainsmtp.star-co.net.kp | — | |
domainmail.silibank.com | — | |
domainhangro.net.kp | — | |
domainsilibank.com | — | |
domainps.ppokkugi.com | — | |
domainfuturere.com.kp | — | |
domainlnnk.com | — | |
domaindns.chinact.net | — | |
domainmail.chinact.net | — | |
domainmx2.sompo-japanchina.com | — | |
domainaeoncredit.com.cn | — | |
domainmall.dssodr.com | — | |
domainhero-huishan.com | — | |
domainhero-huishan.cn | — | |
domainsmtp1.star-co.net.kp | — | |
domainkevin.com | — | |
domainnkinternet.com | — |
Ip
| Value | Description | Copy |
|---|---|---|
ip175.45.176.21 | — | |
ip175.45.178.57 | — | |
ip175.45.178.56 | — | |
ip175.45.177.33 | — | |
ip175.45.176.22 | — | |
ip175.45.176.32 | — | |
ip188.43.136.115 | — | |
ip188.43.136.116 | — | |
ip218.25.43.212 | — | |
ip218.24.140.88 | — | |
ip218.24.140.94 | — | |
ip218.24.140.95 | — | |
ip218.24.161.240 | — | |
ip218.24.161.247 | — | |
ip218.25.125.144 | — | |
ip218.25.125.150 | — | |
ip218.25.125.158 | — | |
ip218.25.125.159 | — | |
ip218.25.171.88 | — | |
ip218.25.171.89 | — | |
ip218.25.43.208 | — | |
ip218.25.43.211 | — | |
ip218.25.43.223 | — | |
ip61.189.49.233 | — | |
ip61.189.49.234 | — | |
ip61.189.49.240 | — |
Hash
| Value | Description | Copy |
|---|---|---|
hashb8810eae6ead0ec3a606300c5e3fe9c7af23f836719596e9519f73b4e1e7ad01 | — | |
hash5a2f81451d6c921a7ab845b1856f67d71c76196cc34ace5ef7c7e8e471c3214b | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttp://silibank.com/fog/update_files/ | — |
Threat ID: 6ab239b9f7a7c54106e66f36
Added to database: 09/22/2026, 08:18:01 UTC
Last enriched: 09/22/2026, 08:35:47 UTC
Last updated: 09/22/2026, 15:04:03 UTC
Views: 10
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.