Glocom, also known as Global Communications Co., is a North Korea-linked front company associated with the DPRK’s sanctions-evasion and military procurement apparatus. It was identified by a United Nations Panel of Experts as a Malaysian defense company acting on behalf of the DPRK and managed by Pan Systems Pyongyang Branch, an entity affiliated with the Reconnaissance General Bureau. Glocom has been associated with the marketing and sale of military communications equipment and has maintained an outward commercial presence despite international sanctions. Glocom is part of a broader DPRK-linked commercial and procurement cluster that includes Future Tech Group and, with high confidence, Hato Tsusin. This cluster has been linked to the promotion, brokerage, and sourcing of communications, RF, navigation, sensor, and related electronics technologies. Evidence tying these entities together includes overlapping infrastructure, shared historical registration artifacts, linked branding and product materials, and interconnected online personas. Hato Tsusin appears to function as a supplier-facing intermediary or broker for components and systems relevant to sanctioned DPRK-linked activity, and its materials have directly referenced Glocom products. Operationally, Glocom has used public-facing websites and product catalogs to advertise battlefield-oriented radio and telecommunications equipment. Reporting also indicates continued promotion of advanced telemetry capabilities relevant to missile guidance. The broader cluster demonstrates procurement tradecraft centered on front companies, deceptive corporate identities, cross-border commercial personas, and infrastructure reuse to support defense-related acquisition and sanctions evasion. Glocom’s dominant role within this ecosystem is as a covert commercial vehicle supporting DPRK military and intelligence-linked objectives.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.