About:

The author is fascinated by North Korea, using OSINT to track its online activity and news.

Website:

Specializations:

Interests:

North Korea OSINT North Korean news Online activity
Subscribe to RSS:
This blog post continues the analysis of the Hangro VPN service, focusing on the authentication mechanisms and recent findings related to its IPs. It discusses the common certificate shared by multiple IPs, the failure of handshak...
The text discusses the discovery of a North Korean server hosting animation files, detailing how it was found and what was exposed, including user activity logs and failed login attempts. It also mentions VPN usage and the duratio...
North Korean IT workers are using GitHub for various reasons, and this post discusses how to find accounts related to IT workers' interests on GitHub. It provides tips on identifying North Korean profiles and mentions a website th...
On March 18, 2025, at around 9:38 AM UTC, connectivity to AS131279 dropped, and a change in the Start of Authority (SOA) record and an update to the Route Origin Authorization (ROA) were detected. The update introduced a new ROA f...
The post discusses the Manbang set top box manual, including its specifications and some interesting details such as the DNS configuration options and the requirement to register with the Manbang Management Center. It also mention...
The post investigates the North Korean VPN infrastructure, particularly focusing on Hangro, a potential VPN for users outside the country. It delves into the IP infrastructure, whois records, and connections to North Korea, sugges...
The text discusses the author's exploration of North Korea's digital map app, including licensing and API insights. It delves into the app's functionality, licensing checks, API calls, map database, and 3rd party libraries. The au...
The text discusses a DNS misconfiguration for korfilm.com.kp, the website for the Korea Film Export & Import Corporation, where one of the entries points to an Apple owned IP instead of a North Korean one. The misconfiguration has...
The text explores the North Korean email client that was leaked, discussing its features and functionality. It is made up of a main executable, dll files, and a config file. The client uses the Chilkat library and references SSH, ...
The text provides information about the 32nd April Spring Friendship Art Festival held in Pyongyang to mark the Day of the Sun. It includes details about the festival, application forms, rules, and contact information.
The text discusses the Rim Jong Hyok indictment and maui ransomware affidavit, highlighting the use of the email whas1985@yahoo.com in various database leaks and the registration of the domain capitalsloan.com by reneefletcher1988...
...