Researchers from FortiGuard Labs have discovered an active campaign spreading the infostealer malware “NordDragonScan,” which targets Microsoft Windows users, amid a recent spike in cyberthreats.
This sophisticated attack leverages compromised websites to deliver a weaponized HTA script that quietly infiltrates victim environments, underscoring the continuing evolution of credential theft methodologies.
Targets Microsoft Windows Environments
The initial infection vector is a shortened link (hxxps://cutt[.]ly/4rnmskDe) that redirects unsuspecting users to a deceptive file-sharing site, secfileshare[.]com.
Here, victims are prompted to download a RAR archive disguised as a legitimate Ukrainian document.
Within this archive, a malicious LNK shortcut leverages mshta.exe to execute a remote HTA payload (“1.hta”).

This script executes a multi-stage attack, first displaying a decoy document to distract the user while copying the legitimate PowerShell.exe to a benign-looking path and ultimately dropping and running a hidden executable (“adblocker.exe”) in the user’s temporary directory.
NordDragonScan is a .NET-based malware, notable for its custom string obfuscation and methodical persistence techniques.
It first ensures a dedicated working directory exists in the victim’s %LOCALAPPDATA% folder as a staging ground for exfiltrated data.
The malware establishes contact with its command-and-control (C2) infrastructure (kpuszkiev[.]com) using uniquely crafted HTTP headers and the victim’s MAC address, enabling dynamic communication with the attacker.
Stealthy Data Theft
For persistence, NordDragonScan creates a startup registry entry under “NordStar” in the Windows Run key, ensuring execution upon system reboot.

It then gathers a wealth of system information, including computer name, user details, OS version, hardware specs, network configuration, and conducts LAN reconnaissance by enumerating live hosts on the local network.
The malware captures a screenshot, harvests Chrome and Firefox browser profiles, and copies files with sensitive extensions (such as .docx, .pdf, and .txt) from key directories.
This data is then uploaded to the C2 server via encrypted channels, allowing attackers to maintain a foothold and request additional information as required.
The campaign leverages several decoy documents, all operating through similar HTA script mechanisms but with varied themes to evade detection and trick users into taking the initial bait.
This systematic approach demonstrates the attackers’ intent to maximize infection rates while bypassing conventional security controls.
The NordDragonScan infostealer poses a significant risk as the stolen information can facilitate future attacks ranging from targeted phishing and business email compromise to broader network intrusions.
Fortinet has updated its threat protection suite to detect and block the various attack components, including the LNK, HTA, and executable payloads.
Their antivirus and CDR services, as well as IP reputation and anti-botnet technologies, are equipped to proactively mitigate this threat.
Organizations are advised to treat suspicious LNK shortcuts and unknown compressed archives with extreme caution.
Security teams should ensure signature updates across all endpoints and consider user training, as highlighted by Fortinet’s educational modules, to bolster awareness of phishing techniques.
For suspected compromises, Fortinet’s global incident response team remains available for consultation and remediation.
Indicators of Compromise (IOC)
| Type | Value |
|---|---|
| Domain | secfileshare[.]com, kpuszkiev[.]com |
| RAR Hash | 2102c2178000f8c63d01fd9199400885d1449501337c4f9f51b7e444aa6fbf50 |
| e07b33b5560bbef2e4ae055a062fdf5b6a7e5b097283a77a0ec87edb7a354725 | |
| 3f3e367d673cac778f3f562d0792e4829a919766460ae948ab2594d922a0edae | |
| HTA Hash | f8403e30dd495561dc0674a3b1aedaea5d6839808428069d98e30e19bd6dc045 |
| fbffe681c61f9bba4c7abcb6e8fe09ef4d28166a10bfeb73281f874d84f69b3d | |
| 39c68962a6b0963b56085a0f1a2af25c7974a167b650cf99eb1acd433ecb772b | |
| 9d1f587b1bd2cce1a14a1423a77eb746d126e1982a0a794f6b870a2d7178bd2c | |
| 7b2b757e09fa36f817568787f9eae8ca732dd372853bf13ea50649dbb62f0c5b | |
| Executable | f4f6beea11f21a053d27d719dab711a482ba0e2e42d160cefdbdad7a958b93d0 |
Find this Story Interesting! Follow us on Google News, LinkedIn, and X to Get More Instant updates