logo

Tracking DPRK operator IPs over time

ID: fa0ecee0-93eb-54e0-a60b-1b13cbc7008b

STIX ID: report--fa0ecee0-93eb-54e0-a60b-1b13cbc7008b

Feed Name: KMsec blog

Threat Score
78/100

Date Published: 2026-02-22

Date Updated: 2026-04-19

...
...

The author details tracking of FAMOUS CHOLLIMA's malicious npm package campaign (Jul 2025–Feb 2026), exposing misuse of insecure temporary-email services that allowed public mailbox access, enumerating attacker-controlled domains/MX records, package names, and a timeline of publishing IPs (including Astrill VPN and TransTeleCom addresses). The piece includes IOCs and hunting recommendations for subscription platforms to block or flag temporary-mail signups and to hunt outbound registration mail to known temp-mail infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.