logo

‘JustJoin’ Landing Page Linked to Suspected DPRK Activity Resurfaces

ID: 5962d715-4e0c-5f61-8e5e-67d620b74487

STIX ID: report--5962d715-4e0c-5f61-8e5e-67d620b74487

Feed Name: Hunt.io Blog

Threat Score
80/100

Date Published: 2026-02-16

Date Updated: 2026-04-28

...
...

Hunt researchers identified a cluster of Hostwinds-hosted servers and domains resolving to IPs (notably 23.254.167.216, 108.174.194.44, and 108.174.194.196) serving a 'JustJoin' landing page linked to TA444/BlueNoroff activity; the analysis highlights domain naming tricks (hex-encoded IP), shared SSH fingerprints across servers, and associated domains that may support phishing or malware delivery. The report provides observables (IPs, domains, hosting AS) and defensive recommendations to monitor HTML hashes and block suspicious domains/IPs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.