Warning: NordDragonScan Malware Attacks Windows Using LOTL Techniques

Just a SOC Analyst ^^
Search for a command to run...

Just a SOC Analyst ^^
No comments yet. Be the first to comment.
Tổng Quan Hãy tưởng tượng: một nhân viên nhân sự tại một công ty hàng không ở Pakistan nhận được lời mời phỏng vấn hấp dẫn từ một thương hiệu tuyển dụng có vẻ rất quen thuộc. Một cuộc gọi video được l

Tóm tắt Ngày 19/03/2026, cơ quan chức năng Mỹ, Canada và Đức triệt phá hạ tầng của bốn botnet IoT lớn nhất từng được ghi nhận — Aisuru, Kimwolf, JackSkid và Mossad. Hơn ba triệu thiết bị bị nhiễm. Hơn

Tóm tắt Không có malware nào trong chiến dịch này. Payload cuối cùng mà nạn nhân nhận được là trình cài đặt chính thức của Level RMM, tải trực tiếp từ hạ tầng của chính Level, cài đặt bằng msiexec với

Phần lớn dữ liệu thu được từ một honeypot SSH internet-facing là nhiễu: dò mật khẩu liên tục, hoặc bot đăng nhập thành công rồi tải payload xuống chạy ngay lập tức. Nhưng ngày 27/6/2026, honeypot của

Từ tháng 1/2025, một nhóm tấn công chưa xác định danh tính đã duy trì hoạt động gián điệp mạng nhắm vào các cơ quan chính phủ tại Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan và Syria,

Security researchers have recently discovered a new information-stealing software named "NordDragonScan," which conducts stealthy attacks on Windows computers using "living-off-the-land" (LOTL) techniques.
Affected Platforms: Microsoft Windows
Affected Users: Microsoft Windows
Impact: Stolen information may be used for future attacks
Severity Level: High
The attacker exploits a shortened link service with the URL “hxxps://cutt[.]ly/4rnmskDe” redirecting to “hxxps://secfileshare[.]com,” which triggers the download of a RAR file named “Укрспецзв_Акт_30_05_25_ДР25_2313_13 від 26_02_2025.rar” (Ukrspetszv_Act_30_05_25_DR25_2313_13 dated 26_02_2025). This file contains a malicious LNK shortcut that silently calls mshta.exe to execute the HTA payload 1.hta from the same server.

Figure 1. LNK File
Next, the malicious HTA file copies a legitimate PowerShell.exe file to the path “C:\Users\Public\Documents\install.exe” to disguise itself. It then downloads an encrypted TXT file, decrypts it, and saves the result as Act300525.doc. This decoy document, titled “Акт здачі-приймання наданих Послуг до договору про надання послуг” (Service Acceptance Act under the Service Agreement), is harmless and intended to distract the user. Finally, the HTA script silently downloads and executes a malicious payload, embedded as an executable file named adblocker.exe, into the victim's directory “\AppData\Local\Temp\adblocker.exe”

Figure 2. HTA File "1.hta"

Figure 3. Decoy Document from "1.hta"
The attacker's server maintains multiple fake files designed to entice user interaction. These decoy files use a similar HTA script mechanism, helping to download and execute the same payload, adblocker.exe, on compromised systems. The reuse of the same executable file across different decoy documents indicates a strategy by the attacker to maximize infection opportunities while using diverse document themes and file names to evade detection and security monitoring.
The malicious payload downloaded from the previous phase is a .NET executable file containing an embedded PDB path: “C:\Users\NordDragon\Documents\visual studio”
NordDragonScan employs string obfuscation techniques, performing XOR operations and byte swapping to hide the code from static analysis. It then checks whether a dedicated working directory “NordDragonScan” exists in the “%LOCALAPPDATA%” directory. If this directory does not exist, it creates a new one to temporarily store stolen data before uploading it to the C2 server.

Figure 4. Checking the Directory
Next, the malware connects to the C2 server, “kpuszkiev.com,” with specific HTTP headers, notably “User-Agent: RTYUghjNM,” along with the victim's MAC address. During the initial connection, the main goal is to obtain a dynamic URL from the C2, which is then used as an endpoint to extract stolen data.

Figure 5. Obtaining the URL for Data Extraction
It then establishes persistence by adding a “NordStar” registry entry to “Software\Microsoft\Windows\CurrentVersion\Run”

Figure 6. Adding Registry for Auto-Launch on Startup
After connecting, NordDragonScan moves to the information-gathering phase on the local machine. It collects basic victim information, including computer name, username, operating system version, architecture, processor count, driver information, and RAM using a combination of WMI and .NET commands. The attacker then lists all active network adapters, extracts the primary IPv4 address and subnet mask, and calculates the CIDR range. The malware then begins a slow scan of each address within the same subnet, creating a catalog of accessible hosts on the same LAN.

Figure 7. Gathering Network Information

Figure 8. Network Scanning
It also captures a screenshot and saves it as “SPicture.png” and collects data from Chrome and Firefox browsers on the victim's machine.

Figure 9 Copying Chrome Data into “Chrm”

Figure 10. Copying Firefox Data
NordDragonScan continues to scan the local file system, including Desktop, Documents, and Downloads folders, and copies files in these directories with the following extensions: “.docx,” “.doc,” “.xls,” “.ovpn,” “.rdp,” “.txt,” and “.pdf.” Once a matching file is found, it copies it into the working directory and groups them by file origin. When the scanning phase is complete, it makes a POST request to the C2 server. This request uses a custom header “User-Agent: Upload,” or “Backups:,” and the name of the data it is preparing to send, such as “sysinfo.txt” for system information.

Figure 11. Stolen Data in the Working Directory

Figure 12. POST Request Sent by Malware to C2 Server
| secfileshare[.]com |
| kpuszkiev[.]com |
| Value | Type | Description | |
| 2102c2178000f8c63d01fd9199400885d1449501337c4f9f51b7e444aa6fbf50 | SHA256 | File RAR hash | |
| e07b33b5560bbef2e4ae055a062fdf5b6a7e5b097283a77a0ec87edb7a354725 | SHA256 | File RAR hash | |
| 3f3e367d673cac778f3f562d0792e4829a919766460ae948ab2594d922a0edae | SHA256 | File RAR hash | |
| f8403e30dd495561dc0674a3b1aedaea5d6839808428069d98e30e19bd6dc045 | SHA256 | File HTA hash | |
| fbffe681c61f9bba4c7abcb6e8fe09ef4d28166a10bfeb73281f874d84f69b3d | SHA256 | File HTA hash | |
| 39c68962a6b0963b56085a0f1a2af25c7974a167b650cf99eb1acd433ecb772b | SHA256 | File HTA hash | |
| 9d1f587b1bd2cce1a14a1423a77eb746d126e1982a0a794f6b870a2d7178bd2c | SHA256 | File HTA hash | |
| 7b2b757e09fa36f817568787f9eae8ca732dd372853bf13ea50649dbb62f0c5b | SHA256 | File HTA hash | |
| f4f6beea11f21a053d27d719dab711a482ba0e2e42d160cefdbdad7a958b93d0 | SHA256 | File executable hash |
FPT Threat Intelligence recommends organizations and individuals take several measures to prevent information-stealing software (infostealer) like NordDragonScan and similar variants:
Enhance Email and Download Control: Implement strict email filtering policies to prevent downloading suspicious compressed files (.rar, .zip) or dangerous HTA scripts (.hta).
Monitor System Execution Behavior: Continuously monitor system processes that may be abused, such as mshta.exe, PowerShell.exe, rundll32.exe, and suspicious behaviors like remote file decryption, creating executables in temporary folders, setting registry entries for persistence, or communicating with Command & Control (C2) servers.
Protect Browser Data and Sensitive Information: Avoid saving automatic login information in Chrome or Firefox browsers.
Configure File and System Access Policies Appropriately: Apply restricted write and execute permissions in directories commonly exploited by malware, such as %LOCALAPPDATA%, %TEMP%. Enhance monitoring of sensitive file formats like .docx, .pdf, .xls, .ovpn, .rdp to prevent data leakage.
Conduct Security Awareness Training for End Users: Equip users with knowledge to identify fake shortcut files, document spoofing techniques, and habits to thoroughly check file origins before opening. Emphasize the importance of not installing software from shortened links or untrusted sharing sites.
Establish Intrusion Detection and Monitoring Systems: Monitor outbound network traffic to detect unusual data transmission to C2 servers, uncommon HTTP headers, or behaviors related to beaconing/heartbeat to unknown domains.