NordDragonScan: Quiet Data-Harvester on Windows

July 14, 2025, 2:17 p.m.

Description

A sophisticated infostealer dubbed NordDragonScan has been discovered, targeting Windows systems through weaponized HTA scripts. The malware is distributed via shortened links leading to RAR archives containing malicious LNK shortcuts. Once installed, NordDragonScan performs extensive reconnaissance, collecting system information, network details, browser data, and sensitive documents. It utilizes custom obfuscation techniques and establishes persistence through registry modifications. The stolen data is exfiltrated to a command-and-control server using TLS encryption. The attack employs various decoy documents to evade detection and maximize infection opportunities. NordDragonScan's capabilities include screenshot capture, Chrome and Firefox profile harvesting, and local network scanning.

Date

  • Created: July 14, 2025, 1:44 p.m.
  • Published: July 14, 2025, 1:44 p.m.
  • Modified: July 14, 2025, 2:17 p.m.

Indicators

  • fbffe681c61f9bba4c7abcb6e8fe09ef4d28166a10bfeb73281f874d84f69b3d
  • f8403e30dd495561dc0674a3b1aedaea5d6839808428069d98e30e19bd6dc045
  • f4f6beea11f21a053d27d719dab711a482ba0e2e42d160cefdbdad7a958b93d0
  • e07b33b5560bbef2e4ae055a062fdf5b6a7e5b097283a77a0ec87edb7a354725
  • 3f3e367d673cac778f3f562d0792e4829a919766460ae948ab2594d922a0edae
  • 9d1f587b1bd2cce1a14a1423a77eb746d126e1982a0a794f6b870a2d7178bd2c
  • 39c68962a6b0963b56085a0f1a2af25c7974a167b650cf99eb1acd433ecb772b
  • 2102c2178000f8c63d01fd9199400885d1449501337c4f9f51b7e444aa6fbf50
  • 7b2b757e09fa36f817568787f9eae8ca732dd372853bf13ea50649dbb62f0c5b
  • kpuszkiev.com
  • secfileshare.com

Attack Patterns