North Korea’s Hangro VPN Infrastructure Exposed by TLS Certificate Leak
Key Takeaways North Korea’s Hangro VPN platform has exposed critical infrastructure details through a misconfigured TLS certificate. The exposed certificate revealed server IP addresses in...
Key Takeaways
- North Korea’s Hangro VPN platform has exposed critical infrastructure details through a misconfigured TLS certificate.
- The exposed certificate revealed server IP addresses in North Korea and Russia, alongside an internal, non-routable IP, offering an unprecedented look into the platform’s architecture.
- Hangro is a state-linked VPN client, not malware, used by North Korean officials and trade representatives abroad to connect to internal systems.
- The discovery highlights vulnerabilities arising from certificate misconfigurations, weak key management, and exposed network metadata.
North Korea’s Hangro platform, a state-linked VPN client, has inadvertently revealed extensive details about its operational infrastructure, which facilitates communication between overseas officials and internal systems. This rare glimpse into North Korea’s digital connectivity was made possible by a misconfigured TLS certificate.
Table Of Content
The newly identified TLS certificate exposed server locations within North Korea and Russia, critically including an internal network address that should never have been publicly accessible. This exposure offers a unique perspective on how North Korean personnel abroad connect to services within the isolated nation, distinguishing it from typical cyber campaigns that often rely on stolen identities and commercial remote access tools.
Hangro itself is not a malicious tool in the conventional sense. It functions as a VPN client, reportedly providing email and real-time chat capabilities for North Korean representatives operating outside the country’s borders.
Leaky TLS Certificate Exposes North Korea’s Hangro VPN Infrastructure
The exposed certificate data was uncovered by Malwarebox during an analysis of a newer management layer deployed around July 2026. Malwarebox said in a report that this discovery established a link between a related service in Pyongyang and hosts situated in Russia’s Far East. Furthermore, it unveiled older infrastructure previously located within Chinese address space.
While this finding does not confirm the platform’s involvement in any specific intrusion, it underscores how fundamental errors in certificate management, inadequate key handling, and the exposure of network metadata can compromise sensitive infrastructure, even when operators employ client certificates and non-standard network ports to restrict access.
The TLS certificate, observed on port 6006, listed five public IP addresses: three in North Korea and two in Russia. Crucially, it also contained the internal IP address 100.100.100.170, which belongs to carrier-grade NAT space and is not publicly routable. Its inclusion in a public-facing certificate effectively disclosed a portion of the deployment’s internal network addressing scheme. The full details of the exposed infrastructure can be found in the research paper.
The same management certificate was observed on 175.45.176.21 in Pyongyang and on the Russian systems at 188.43.136.115 and 188.43.136.116. This consistent certificate deployment, coupled with service exposure and mutual TLS requirements, suggests a centrally managed environment, although the report refrains from definitively asserting a single control system. Such certificate reuse provides a crucial advantage for threat intelligence, allowing researchers to correlate seemingly disparate servers and monitor changes, as has been seen in previous analyses of DPRK infrastructure.
The newer Hangro service appears to be more robustly configured than its older VPN and mail components. The service on port 6006 successfully completed a TLS 1.3 handshake and enforced client certificate authentication. In contrast, services on ports 465 and 7443 generated “bad-signature” errors, indicating that these older servers lacked the private keys corresponding to the certificates they presented. This detail is further elaborated in the report.
Broken Keys and Overseas Access
A significant finding was the failure of every signature in Hangro’s 2024 certificate chain to verify, including the root certificate against itself. This strongly suggests that the private keys in use do not match the public keys embedded in the certificates. While Malwarebox indicated that definitive confirmation would necessitate access to the signing environment, this misconfiguration is a critical flaw. The full analysis is available in the report.
This weakness is particularly relevant because the Hangro client reportedly bypasses standard certificate validation, trusting certificates installed with the software regardless of their signature chain integrity. Consequently, the platform can continue to operate with a certificate setup that would typically be rejected by common browsers, mail clients, and most security products.
The
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.