Security1 publisher3 min readPublished
Hangro's new server certificate lists every host North Korea's VPN operators claim
A certificate hierarchy that went live on port 6006 around July 2026 enumerates the machines behind Pyongyang's state VPN. Robin Dost traced one thread from it to six Chinese network assignments under a single registry contact.
The Watch · Security desk

What happened
- Around July 2026 a second certificate hierarchy went live on port 6006 on the Hangro hosts in Pyongyang and the Russian Far East, running beside the 2024 hierarchy that is still in service.
- Following that entry led Dost to six network assignments in Chinese address space tracing to a single registry contact, a twenty-five year old mail service and a chain where no signature verifies.
- The 2024 VPN leaf certificate for hangro.net.kp, and the private key behind it, are served byte for byte identically from the North Korean and the Russian hosts.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- capability One TLS handshake on port 6006 now yields the operators' own host list, current as of the day they provisioned the certificate. Collecting that inventory usually takes sustained scanning or access to a client.
- exposure Every name in that field is a target anyone can work from, and the host Dost flags as unintended is the one the operators had no plan to defend as public.
- decision For enterprises, the step this supports is a driver-inventory query for NeoAdapter_VPN devices whose description reads HangroVPN Adapter.
- precedent The 2024 provisioning gave hunters a single fingerprint to chase; the 2026 provisioning gave them a roster.
A subject alternative name field is the list of names a server will answer for, and whoever provisions the certificate writes it. On the three 2024 leaves that field was empty [15]. The certificate on port 6006 carries the operators' inventory instead: every machine they count as part of Hangro, and one host Dost says they probably did not mean to publish [4].
Dost is explicit about provenance. "Read this more as an update, not as a full discovery piece of mine," he wrote [6]. Nick Roy has been documenting Hangro since January 2025, with a second part in July and an infrastructure update that November [7], and wrote about futurere.com.kp and one of the endpoint addresses in 2019 [25].
The 2024 chain runs four deep: HBS2024 self-signed on 14 February 2024, isca2024 on 19 February with pathlen:1, hrra2024 on 20 May with pathlen:0 [13]. Three leaves followed on 27 May, on adjacent serials, inside one hour 55 minutes and 21 seconds of each other [14][24]. hrpostfix is SMTP, hrdovecot is IMAP and POP, hangro.net.kp is the VPN [16]. All four share a single extension template of clientAuth, serverAuth and emailProtection [15]. Every validity period is five years, so the root stands until 14 February 2029, about 31 months past the point where the new hierarchy appeared [23].
The best pivot in the older chain is the VPN leaf, SHA-256 b8810eae6ead0ec3a606300c5e3fe9c7af23f836719596e9519f73b4e1e7ad01, served byte for byte identically from 175.45.176.21, .22 and .32 in North Korean space and 188.43.136.115 and .116 in Russian space [17][12]. The same private key sits on both sides of that border.
The client's lineage is in public driver databases. Two aggregator sites carry metadata for a network driver called HangroVPN Adapter with hardware ID NeoAdapter_VPN, version 1.1.0.7105 dated 24 January 2013 and version 4.2.8 dated 9 September 2014 [19]. NeoAdapter_VPN is SoftEther's own hardware ID, verbatim in the upstream Neo6 driver INF; Hangro renamed the device description and left the ID alone [20]. Roy reached the same conclusion from sample analysis [18]. The telemetry came from a Dell Inspiron 570 running Windows 7 Ultimate K, the Korean market edition [21]. A NeoAdapter_VPN device presenting as HangroVPN Adapter in an endpoint driver inventory is Hangro.
Who holds seats is what gives the host list value. RFA reported in September 2022 that North Korean trade representatives in Jilin, Liaoning and Heilongjiang had been ordered that August to install Hangro, distributed through the consulate in Shenyang at 350 US dollars a seat [10]. A source in Dandong described it as the only email channel between the authorities and the company, according to that report [11]. A page on ps.ppokkugi.com carrying the Hangro icon describes the product as a service for visitors who are away from the fatherland [9].
Dost ties the six Chinese network assignments to one registry contact, a twenty-five year old mail service, and a chain in which no signature verifies, including the self-signed root against itself [5]. He does not identify the netblocks, the contact or the mail service in his summary [27].
What to watch
- Publication of the six netblocks and the registry contact, which would let others confirm the Chinese address space link independently.
- Whether the 2024 hierarchy is retired or both chains keep serving on port 6006 in Pyongyang and the Russian Far East.
- Whether the shared hangro.net.kp key is rotated now that its fingerprint and its five serving hosts are public.