DRAGSTARE
DRAGSTARE is a C# information-stealing malware used by the UAC-0099 threat actor in phishing-driven cyberespionage campaigns targeting Ukrainian state authorities, the Defense Forces of Ukraine, and defense-industrial enterprises. It is typically deployed as a follow-on payload by the MATCHBOIL loader alongside the MATCHWOK backdoor. Reported initial access involves phishing emails, often themed as court summons and sent via UKR.NET, linking to legitimate file-hosting services that deliver a double archive containing an HTA file; execution of the HTA launches obfuscated VBScript and PowerShell that ultimately activates MATCHBOIL, which then deploys DRAGSTARE.
DRAGSTARE is described as a stealer focused on broad host and user data collection. High-confidence capabilities mentioned in the source material include collecting system information; stealing browser data from Chrome and Mozilla browsers, including credentials, cookies, and decryption keys; copying files matching specified extensions from common user folders such as Desktop, Documents, and Downloads; capturing screenshots; archiving/staging collected data for exfiltration; and executing PowerShell commands received from attacker-controlled infrastructure. Reporting also notes anti-analysis or evasion behavior, including virtual machine checks, and persistence via a registry key. Exfiltration is performed to a dynamic URL obtained from command-and-control infrastructure. The malware is also referred to in one source as NordDragonScan.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Techniques & procedures
7 distinct techniques documented for this family, organized by ATT&CK tactic.
Recent activity
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as part of the updated toolset of UAC-0099.
A C# infostealer that collects system information, browser data, files, and screenshots, then exfiltrates them to a remote server.
A C# infostealer that collects system information, browser data, files, and screenshots, then exfiltrates them to a remote server.
Tool/malware component referenced as part of the UAC-0099 toolkit update.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.