Researchers examining Hangro, a North Korean state-linked VPN, mail, and chat service, found a defective 2024 elliptic-curve certificate hierarchy on VPN and mail endpoints in North Korea and Russia: none of the certificates’ signatures validate, and the affected services do not appear to hold private keys corresponding to the certificates they present. Earlier testing of Hangro hosts on port 7443 found they shared a hangro.net.kp certificate issued by an apparent internal hrra2024 CA and appeared to require client certificates, preventing ordinary direct TLS connections.
Reverse engineering of an older Hangro client showed it obtains a PEM certificate locally from port 6279, decrypts an embedded private key with the password 1234, and uses GOST cryptography and token-authentication libraries. A separate RSA-based management TLS hierarchy, observed on port 6006 in July 2026, uses mutual TLS and exposes SAN entries for Hangro systems in Pyongyang and Russia’s Far East, plus an internal carrier-grade NAT address. The infrastructure and a Hangro icon on a North Korean website support the assessment that the service provides DPRK personnel and trade representatives abroad interactive access to domestic systems, potentially using Russian connectivity alongside other external routes.

TTPs, infrastructure, and targeting history in one profile.
6 events from the most recent confirmed update back to the earliest known activity.
A separate RSA-4096 management certificate hierarchy issued by “KEVIN ROOT CA” appeared on port 6006. The service used mutual TLS and exposed SANs for Hangro-related North Korean and Russian addresses plus internal CGNAT address 100.100.100.170.
The two Russian Hangro hosts exposed port 6008 with a distinct malformed X.509 v1 certificate dated June 2026; North Korean hosts did not expose that port.
Hangro’s VPN and mail infrastructure used an intended four-level EC P-384 PKI hierarchy comprising HBS2024, isca2024, hrra2024, and certificates for hrpostfix, hangro.net.kp, and hrdovecot.
North Korean trade representatives in Jilin, Liaoning, and Heilongjiang were reportedly ordered to install Hangro. Distribution was handled through the DPRK consulate in Shenyang at an approximate cost of US$350 per seat.
Silibank.com historically hosted Hangro installer files in a fog/update_files directory; the directory name corresponds to the client’s Korean “fog” branding.
The Hangro icon, previously observed on ps.ppokkugi.com and described in its source as a service for visitors away from home, no longer appeared on the site around July 18.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 39 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
blog.synapticsystems.de
Open sourcenkinternet.com
Open source38north.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.