Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Microsoft Entra ID to Block SMS First-Factor Sign-Ins Globally in February 2027
September 21, 2026
Payload Ransomware Abuses Group Policy to Disrupt Windows Domains
September 21, 2026
Malicious npm Package Hides Malware in Runtime Code
September 21, 2026
Home/CyberSecurity News/North Korea’s Hangro VPN Infrastructure Exposed by TLS Certificate Leak
CyberSecurity News

North Korea’s Hangro VPN Infrastructure Exposed by TLS Certificate Leak

Key Takeaways North Korea’s Hangro VPN platform has exposed critical infrastructure details through a misconfigured TLS certificate. The exposed certificate revealed server IP addresses in...

Jennifer sherman
Jennifer sherman
September 21, 2026 3 Min Read
3 0

Key Takeaways

  • North Korea’s Hangro VPN platform has exposed critical infrastructure details through a misconfigured TLS certificate.
  • The exposed certificate revealed server IP addresses in North Korea and Russia, alongside an internal, non-routable IP, offering an unprecedented look into the platform’s architecture.
  • Hangro is a state-linked VPN client, not malware, used by North Korean officials and trade representatives abroad to connect to internal systems.
  • The discovery highlights vulnerabilities arising from certificate misconfigurations, weak key management, and exposed network metadata.

North Korea’s Hangro platform, a state-linked VPN client, has inadvertently revealed extensive details about its operational infrastructure, which facilitates communication between overseas officials and internal systems. This rare glimpse into North Korea’s digital connectivity was made possible by a misconfigured TLS certificate.

Table Of Content

  • Key Takeaways
  • Leaky TLS Certificate Exposes North Korea’s Hangro VPN Infrastructure
  • Broken Keys and Overseas Access

The newly identified TLS certificate exposed server locations within North Korea and Russia, critically including an internal network address that should never have been publicly accessible. This exposure offers a unique perspective on how North Korean personnel abroad connect to services within the isolated nation, distinguishing it from typical cyber campaigns that often rely on stolen identities and commercial remote access tools.

Hangro itself is not a malicious tool in the conventional sense. It functions as a VPN client, reportedly providing email and real-time chat capabilities for North Korean representatives operating outside the country’s borders.

Leaky TLS Certificate Exposes North Korea’s Hangro VPN Infrastructure

The exposed certificate data was uncovered by Malwarebox during an analysis of a newer management layer deployed around July 2026. Malwarebox said in a report that this discovery established a link between a related service in Pyongyang and hosts situated in Russia’s Far East. Furthermore, it unveiled older infrastructure previously located within Chinese address space.

While this finding does not confirm the platform’s involvement in any specific intrusion, it underscores how fundamental errors in certificate management, inadequate key handling, and the exposure of network metadata can compromise sensitive infrastructure, even when operators employ client certificates and non-standard network ports to restrict access.

The TLS certificate, observed on port 6006, listed five public IP addresses: three in North Korea and two in Russia. Crucially, it also contained the internal IP address 100.100.100.170, which belongs to carrier-grade NAT space and is not publicly routable. Its inclusion in a public-facing certificate effectively disclosed a portion of the deployment’s internal network addressing scheme. The full details of the exposed infrastructure can be found in the research paper.

The same management certificate was observed on 175.45.176.21 in Pyongyang and on the Russian systems at 188.43.136.115 and 188.43.136.116. This consistent certificate deployment, coupled with service exposure and mutual TLS requirements, suggests a centrally managed environment, although the report refrains from definitively asserting a single control system. Such certificate reuse provides a crucial advantage for threat intelligence, allowing researchers to correlate seemingly disparate servers and monitor changes, as has been seen in previous analyses of DPRK infrastructure.

The newer Hangro service appears to be more robustly configured than its older VPN and mail components. The service on port 6006 successfully completed a TLS 1.3 handshake and enforced client certificate authentication. In contrast, services on ports 465 and 7443 generated “bad-signature” errors, indicating that these older servers lacked the private keys corresponding to the certificates they presented. This detail is further elaborated in the report.

Broken Keys and Overseas Access

A significant finding was the failure of every signature in Hangro’s 2024 certificate chain to verify, including the root certificate against itself. This strongly suggests that the private keys in use do not match the public keys embedded in the certificates. While Malwarebox indicated that definitive confirmation would necessitate access to the signing environment, this misconfiguration is a critical flaw. The full analysis is available in the report.

This weakness is particularly relevant because the Hangro client reportedly bypasses standard certificate validation, trusting certificates installed with the software regardless of their signature chain integrity. Consequently, the platform can continue to operate with a certificate setup that would typically be rejected by common browsers, mail clients, and most security products.

The

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackMalwareSecurityThreat

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

ChatGPT Ad Tracking Cookie Exposes User Activity Across Third-Party Sites

Next Post

Malicious npm Package Hides Malware in Runtime Code

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Microsoft Confirms September 2026 Windows Updates Break File History Backups
September 21, 2026
North Korean Hackers Use Fake Terraform Jobs to Deploy macOS Backdoors
September 21, 2026
Critical HEIF Image Vulnerability Exploited for Remote Code Execution
September 21, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us