DRAGSTARE is a C# information-stealing malware family associated with the Russia-aligned UAC-0099 threat cluster and used in cyber-espionage campaigns targeting Ukrainian government, defense, and defense-industrial organizations. It is commonly deployed as a follow-on payload in intrusion chains where the MATCHBOIL loader delivers additional tooling, including the MATCHWOK backdoor and DRAGSTARE stealer, after phishing-based initial access.
The malware is designed to collect extensive host and user data from compromised Windows systems. Reported functionality includes gathering system information, stealing credentials and other browser data from Chrome- and Mozilla-based browsers, including passwords, cookies, and browser decryption material, collecting screenshots, and searching for files matching selected extensions in common user directories such as Desktop, Documents, and Downloads. DRAGSTARE stages and archives stolen data for exfiltration and can transmit the collected material to attacker-controlled infrastructure.
Beyond theft, DRAGSTARE has been reported to execute PowerShell commands received from command-and-control, giving operators limited post-compromise tasking capability in addition to collection. The malware also employs anti-analysis and evasion measures, including checks intended to avoid execution in virtualized or analysis environments. Persistence has also been reported in some campaigns.
Operationally, DRAGSTARE appears as part of UAC-0099’s evolving toolkit, which has been used in phishing campaigns leveraging archive-delivered scripts, HTA or VBScript execution chains, and trojanized software components to compromise victims and deploy espionage tooling. Its role within these operations is focused on credential theft, browser data theft, document collection, screenshot capture, and exfiltration from targeted Windows endpoints.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
CERT-UA published a new advisory attributing a phishing campaign to UAC-0099, a Russia-aligned threat actor active since at least mid-2022 and previously known for exploiting WinRAR vulnerabilities and using phishing emails to deliver malware families including LONEPAGE, MATCHBOIL, and DRAGSTARE.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Previously used malware family associated with earlier UAC-0099 phishing campaigns.
A malware family previously deployed by UAC-0099 via phishing emails.
Previously observed malware associated with earlier UAC-0099 campaigns; mentioned as historical context alongside MATCHBOIL.
Referenced as part of the updated toolset of UAC-0099.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.