惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

GbyAI
GbyAI
Y
Y Combinator Blog
Recent Announcements
Recent Announcements
D
Docker
Blog — PlanetScale
Blog — PlanetScale
罗磊的独立博客
美团技术团队
V
V2EX
Last Week in AI
Last Week in AI
D
DataBreaches.Net
T
The Blog of Author Tim Ferriss
宝玉的分享
宝玉的分享
Microsoft Security Blog
Microsoft Security Blog
Microsoft Azure Blog
Microsoft Azure Blog
人人都是产品经理
人人都是产品经理
M
MIT News - Artificial intelligence
P
Proofpoint News Feed
B
Blog RSS Feed
博客园_首页
B
Blog
博客园 - 叶小钗
I
InfoQ
WordPress大学
WordPress大学
L
LangChain Blog
Apple Machine Learning Research
Apple Machine Learning Research
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
A
About on SuperTechFans
The GitHub Blog
The GitHub Blog
The Register - Security
The Register - Security
MyScale Blog
MyScale Blog
云风的 BLOG
云风的 BLOG
博客园 - 司徒正美
Latest news
Latest news
W
WeLiveSecurity
T
The Exploit Database - CXSecurity.com
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
aimingoo的专栏
aimingoo的专栏
小众软件
小众软件
Cyberwarzone
Cyberwarzone
Scott Helme
Scott Helme
D
Darknet – Hacking Tools, Hacker News & Cyber Security
C
CERT Recently Published Vulnerability Notes
C
CXSECURITY Database RSS Feed - CXSecurity.com
Recent Commits to openclaw:main
Recent Commits to openclaw:main
N
News and Events Feed by Topic
S
Secure Thoughts
The Hacker News
The Hacker News
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Google DeepMind News
Google DeepMind News

North Korean Internet

DPRK Captive Portal Infrastructure Found in Testing More Fake Devs, More Fake Companies: vexxloso and Nixsora.com npm Malware, Fake Devs, and Deepfake Videos: These Are A Few of My Favorite DPRK Things Made for Export: North Korea’s Software Catalog Kwangmyong Additional Notes on the Trevor Greer Infostealer Logs Hunting For North Korean Fiber Optic Cables Unboxing the Arirang 182 – A North Korean Feature Phone Hangro: Investigating North Korean VPN Infrastructure Part 2
DPRK Infrastructure Update
nick · 2025-11-20 · via North Korean Internet

While it’s pretty well known that the DPRK is assigned ASN131279 there are a handful of other ranges that they seemingly have access to. Based on the names these appear to be assigned to the DPRK via Russia TransTelekom

CIDRASNNetnameCompany
62.33.81.0/2420485KPOST-NETTTK-DV
80.237.84.0/2420485KPOST-NETTTK-DV
188.43.88.0/2420485KPOST-NETTTK-DV
188.43.136.0/2420485KPOST-NET2TTK-DV

And while not as explicitly named they are also using

45.126.3.0/24134544Cenbong Int’l Holdings

These make sense as both 20485 and 134544 are upstream peers of ASN 131279

There are also a handful of other ranges that they are leveraging. The first two are also part of TTK and the final one I haven’t seen evidence of being in use but the abuse contact email for the IPs are postmaster@silibank.com and the company listed is Liaoning Clear channel data Communication, Inc which is right over the border from the DPRK in China.

80.237.87.0/2420485SKYFREIGHT-NET
83.234.227.0/2420485SKYFREIGHT-NET
218.25.43.208/284837China Unicom

Now, I’ve been working on some more detailed infrastructure write ups but one thing that stood out last year was a note on an ITW account that listed information about proxying traffic via Russia and Hong Kong. Note is below:

The following IPs are also used for traffic leaving the country via NetKey/OConnect

  • 45.126.3.252
  • 83.234.227.41

Discover more from North Korean Internet

Subscribe to get the latest posts sent to your email.