DRAGSTARE, also known as NordDragonScan, is a C#/.NET information stealer targeting Windows systems. It is used by UAC-0099, also tracked as Earth Sirrush, in cyberespionage campaigns against Ukrainian government agencies, military personnel, and defense-industrial organizations. It is deployed as a follow-on payload by MATCHBOIL, alongside the MATCHWOK backdoor. Associated infection chains begin with targeted phishing emails, including court-summons-themed lures, that direct recipients to file-sharing services hosting archives containing malicious scripts.
DRAGSTARE collects system and network information, steals passwords, cookies, and browser decryption keys from Google Chrome and Mozilla Firefox, captures screenshots, and gathers files selected by extension from common user folders, including the desktop, documents, and downloads. Collected files are staged and archived before exfiltration to an endpoint supplied by its command-and-control server. The malware also supports execution of attacker-supplied PowerShell commands and subnet scanning. Its evasion features include virtual-machine checks and XOR-based string encryption shared with MATCHBOIL and ASHVEIN. DRAGSTARE maintains persistence through Windows registry modifications.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Other malicious tools have also been associated with MATCHBOIL, including MATCHWOK, a backdoor that enables the execution of remote commands, and DRAGSTARE, a cookie and browser credential stealer.
Structurally identical XOR-based string encryption across ASHVEIN, MATCHBOIL, and DRAGSTARE.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cookie and browser credential stealer associated with MATCHBOIL in UAC-0099's toolset, supporting information theft from compromised systems.
C# information stealer discussed as a comparison with ASHVEIN. It steals browser credentials, captures screenshots, collects files, and performs WMI-based system fingerprinting. It also includes anti-VM checks and subnet scanning. Separate developer accounts and build environments suggest parallel development of tools serving similar operational requirements.
Information stealer that extracts browser passwords, cookies and desktop files. UAC-0099 deployed it through MatchBoil in an espionage campaign targeting Ukrainian government, military and defense organizations.
Previously used malware family associated with earlier UAC-0099 phishing campaigns.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.