North Korea’s Hangro Revisited
2026-09-20 • Synaptic Security •
https://blog.synapticsystems.de/north-koreas-hangro-revisited/
Synaptic Security maps Hangro, a North Korean state VPN, email, and real-time chat product derived from SoftEther and distributed to DPRK trade representatives abroad. The research documents a broken 2024 elliptic-curve certificate hierarchy alongside a separate RSA-based management layer deployed in July 2026 across hosts in Pyongyang and the Russian Far East, with one certificate exposing five public addresses and an internal carrier-grade NAT address. It also traces Hangro’s default Chinese endpoint through six China Unicom assignments tied to a historical Silibank registry contact and reconstructs the evolution from Silibank’s leased-line mail service to certificate-bound VPN and mail infrastructure. The analysis separates commercial dead drops, operator activity in China, state mail relays, Hangro access, and physical couriering as different layers of DPRK communications rather than a single return channel.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | hangro.net.kp | 2026-09-20 | 2026-09-20 |
| IPv4 | 218.25.43.212 | 2025-01-06 | 2026-09-20 |
| IPv4 | 175.45.176.32 | 2025-01-06 | 2026-09-20 |
| IPv4 | 175.45.176.21 | 2025-01-06 | 2026-09-20 |
| IPv4 | 188.43.136.116 | 2025-01-06 | 2026-09-20 |
| IPv4 | 175.45.176.22 | 2025-01-06 | 2026-09-20 |
| IPv4 | 188.43.136.115 | 2025-01-06 | 2026-09-20 |