NordDragonScan Launches Credential-Stealing Attacks on Windows Users

Researchers from FortiGuard Labs have discovered an active campaign spreading the infostealer malware “NordDragonScan,” which targets Microsoft Windows users, amid a recent spike in cyberthreats.

This sophisticated attack leverages compromised websites to deliver a weaponized HTA script that quietly infiltrates victim environments, underscoring the continuing evolution of credential theft methodologies.

Targets Microsoft Windows Environments

The initial infection vector is a shortened link (hxxps://cutt[.]ly/4rnmskDe) that redirects unsuspecting users to a deceptive file-sharing site, secfileshare[.]com.

Here, victims are prompted to download a RAR archive disguised as a legitimate Ukrainian document.

Within this archive, a malicious LNK shortcut leverages mshta.exe to execute a remote HTA payload (“1.hta”).

NordDragonScan
LNK file

This script executes a multi-stage attack, first displaying a decoy document to distract the user while copying the legitimate PowerShell.exe to a benign-looking path and ultimately dropping and running a hidden executable (“adblocker.exe”) in the user’s temporary directory.

NordDragonScan is a .NET-based malware, notable for its custom string obfuscation and methodical persistence techniques.

It first ensures a dedicated working directory exists in the victim’s %LOCALAPPDATA% folder as a staging ground for exfiltrated data.

The malware establishes contact with its command-and-control (C2) infrastructure (kpuszkiev[.]com) using uniquely crafted HTTP headers and the victim’s MAC address, enabling dynamic communication with the attacker.

Stealthy Data Theft

For persistence, NordDragonScan creates a startup registry entry under “NordStar” in the Windows Run key, ensuring execution upon system reboot.

NordDragonScan
registry

It then gathers a wealth of system information, including computer name, user details, OS version, hardware specs, network configuration, and conducts LAN reconnaissance by enumerating live hosts on the local network.

The malware captures a screenshot, harvests Chrome and Firefox browser profiles, and copies files with sensitive extensions (such as .docx, .pdf, and .txt) from key directories.

This data is then uploaded to the C2 server via encrypted channels, allowing attackers to maintain a foothold and request additional information as required.

The campaign leverages several decoy documents, all operating through similar HTA script mechanisms but with varied themes to evade detection and trick users into taking the initial bait.

This systematic approach demonstrates the attackers’ intent to maximize infection rates while bypassing conventional security controls.

The NordDragonScan infostealer poses a significant risk as the stolen information can facilitate future attacks ranging from targeted phishing and business email compromise to broader network intrusions.

Fortinet has updated its threat protection suite to detect and block the various attack components, including the LNK, HTA, and executable payloads.

Their antivirus and CDR services, as well as IP reputation and anti-botnet technologies, are equipped to proactively mitigate this threat.

Organizations are advised to treat suspicious LNK shortcuts and unknown compressed archives with extreme caution.

Security teams should ensure signature updates across all endpoints and consider user training, as highlighted by Fortinet’s educational modules, to bolster awareness of phishing techniques.

For suspected compromises, Fortinet’s global incident response team remains available for consultation and remediation.

Indicators of Compromise (IOC)

TypeValue
Domainsecfileshare[.]com, kpuszkiev[.]com
RAR Hash2102c2178000f8c63d01fd9199400885d1449501337c4f9f51b7e444aa6fbf50
e07b33b5560bbef2e4ae055a062fdf5b6a7e5b097283a77a0ec87edb7a354725
3f3e367d673cac778f3f562d0792e4829a919766460ae948ab2594d922a0edae
HTA Hashf8403e30dd495561dc0674a3b1aedaea5d6839808428069d98e30e19bd6dc045
fbffe681c61f9bba4c7abcb6e8fe09ef4d28166a10bfeb73281f874d84f69b3d
39c68962a6b0963b56085a0f1a2af25c7974a167b650cf99eb1acd433ecb772b
9d1f587b1bd2cce1a14a1423a77eb746d126e1982a0a794f6b870a2d7178bd2c
7b2b757e09fa36f817568787f9eae8ca732dd372853bf13ea50649dbb62f0c5b
Executablef4f6beea11f21a053d27d719dab711a482ba0e2e42d160cefdbdad7a958b93d0

Find this Story Interesting! Follow us on Google NewsLinkedIn, and X to Get More Instant updates

Mandvi
Mandvi
Mandvi is a Security Reporter covering data breaches, malware, cyberattacks, data leaks, and more at Cyber Press.

Trending News

Related Stories