MATCHBOIL Malware Uses Cloudflare-Hidden C2 Servers to Deliver Backdoor Payloadsnew
UAC-0099's MATCHBOIL downloader hides C2 behind Cloudflare and delivers MATCHWOK to Ukrainian firms.
ESET documented MATCHBOIL, a C# downloader linked to UAC-0099, across samples from April 2024 to April 2026. Infections were recorded at Ukrainian transportation companies in July and August 2025, a manufacturer in December 2025, and an energy company in June 2026. Phishing links lead victims to run a VBScript that installs MATCHBOIL, which then retrieves MATCHWOK over HTTPS from servers hidden behind Cloudflare. Later versions use Eziriz .NET Reactor, debugger and uptime checks, two-minute C2 polling, and mail-themed scheduled tasks. ESET assesses alignment with Russian interests at medium confidence.