NordDragonScan Attacking Windows Users to Steal Login Credentials
Security researchers have uncovered a new high-severity cyberattack campaign targeting Microsoft Windows users through a sophisticated infostealer malware called “NordDragonScan.”
Security researchers have uncovered a new high-severity cyberattack campaign targeting Microsoft Windows users through a sophisticated infostealer malware called “NordDragonScan.”
The malware employs advanced techniques to steal login credentials, browser data, and sensitive documents from compromised systems.
Advanced Delivery Method Exploits User Trust
FortiGuard Labs recently discovered an active delivery infrastructure hosting weaponized HTA scripts that silently deploy the NordDragonScan infostealer into victims’ environments.
The attack begins with shortened URL services that redirect users to what appears to be legitimate file-sharing platforms, triggering the download of RAR archives with Ukrainian filenames designed to appear as official documents.
The malicious package contains a crafted LNK shortcut file that automatically executes Microsoft’s mshta.exe utility to run the embedded HTA payload.
This technique allows attackers to bypass many security measures by using legitimate Windows tools for malicious purposes.
The HTA script then copies PowerShell.exe to a public directory and renames it as “install.exe” to mask its presence from security software.
Once installed, NordDragonScan demonstrates extensive data collection capabilities that pose significant risks to victim privacy and security.
The malware systematically examines the host system, taking screenshots and harvesting complete Chrome and Firefox browser profiles containing saved passwords, browsing history, and other sensitive information.
The malicious package contains a crafted LNK shortcut file that automatically executes Microsoft’s mshta.exe utility to run the embedded HTA payload.
The infostealer targets specific file types across key directories including Desktop, Documents, and Downloads folders. It specifically searches for documents with extensions including .docx, .doc, .xls, .ovpn, .rdp, .txt, and .pdf files.
The malware also conducts network reconnaissance, scanning the victim’s local area network to identify other potentially vulnerable systems.
NordDragonScan establishes persistence on infected systems by creating registry entries that ensure the malware continues operating across system reboots.
The malware communicates with its command-and-control server “kpuszkiev.com” using custom HTTP headers and encrypted TLS connections to exfiltrate stolen data.
The C2 infrastructure serves dual purposes as both a data collection point and a heartbeat server, allowing attackers to confirm victims remain online and request additional data when needed.
This sophisticated approach enables long-term monitoring and data extraction from compromised systems.
Beyond individual system compromise, NordDragonScan poses broader network security risks through its network scanning capabilities.
The malware enumerates network adapters, calculates CIDR ranges, and conducts lightweight probes across the local network infrastructure.
This functionality allows attackers to identify and potentially compromise additional systems within the same network environment.
Security experts recommend extreme caution when handling LNK shortcuts and compressed archives from untrusted sources.
Organizations should implement comprehensive email security measures, maintain updated antivirus software, and educate users about social engineering tactics employed in these campaigns.
The sophisticated nature of NordDragonScan demonstrates the evolving threat landscape facing Windows users.
Its ability to operate stealthily while systematically harvesting sensitive data makes it particularly dangerous for both individual users and organizational networks.
Regular security awareness training and robust endpoint protection remain critical defenses against such advanced persistent threats .
Investigate live malware behavior, trace every step of an attack, and make faster, smarter security decisions -> Try ANY.RUN now
Based on reporting by Cyber Security News.
