MATCHBOIL Malware Uses Cloudflare-Hidden C2 Servers to Deliver Backdoor Payloads
UAC-0099's MATCHBOIL downloader hides C2 behind Cloudflare and delivers MATCHWOK to Ukrainian firms.
ESET documented MATCHBOIL, a C# downloader linked to UAC-0099, across samples from April 2024 to April 2026. Infections were recorded at Ukrainian transportation companies in July and August 2025, a manufacturer in December 2025, and an energy company in June 2026. Phishing links lead victims to run a VBScript that installs MATCHBOIL, which then retrieves MATCHWOK over HTTPS from servers hidden behind Cloudflare. Later versions use Eziriz .NET Reactor, debugger and uptime checks, two-minute C2 polling, and mail-themed scheduled tasks. ESET assesses alignment with Russian interests at medium confidence.
- MATCHBOIL is a C# downloader used by UAC-0099 against Ukraine.
- Observed victims include transport, manufacturing, and energy firms.
- It downloads MATCHWOK over HTTPS from Cloudflare-hidden servers.
- Newer builds add .NET Reactor, anti-analysis checks, and scheduled tasks.
- CERT-UA names the April 2026 DLL variant MATCHBOIL.V2.
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | airarticlegenerate.com | 2025-08-12 flycloud-service[.]com 64.95.10[.]223 2026-03-03 airarticlegenerate[.]com 64.95.13[.]210 2025-05-07 Type Host indicators Directorie |
| domain | flycloud-service.com | isted 2025-11-10 telemetry-conf[.]com Not listed 2025-08-12 flycloud-service[.]com 64.95.10[.]223 2026-03-03 airarticlegenerate[.]com 64.95. |
| domain | telemetry-conf.com | First seen virtualdailyplanner[.]pro Not listed 2025-11-10 telemetry-conf[.]com Not listed 2025-08-12 flycloud-service[.]com 64.95.10[.]2 |
| domain | virtualdailyplanner.pro | 4F0B3A8A098E60B76D10FB06B14 C2 domain IP address First seen virtualdailyplanner[.]pro Not listed 2025-11-10 telemetry-conf[.]com Not listed 202 |
| sha1 | 026f892630d0a4fe854a75984695ba99af0022c4 | exe A926889BAB31F3C34663D18C05C4E862EF367028 bootloader.exe 026F892630D0A4FE854A75984695BA99AF0022C4 PlannerAssistantManager.exe F886B615CB9E23EAD2718FF2A61155A |
| sha1 | 050926727cdd74f0b3a8a098e60b76d10fb06b14 | 188C8C88CFC69476F836E7 April-2026 DLL; filename unspecified 050926727CDD74F0B3A8A098E60B76D10FB06B14 C2 domain IP address First seen virtualdailyplanner[.]pro N |
Full article826 words · extracted from cybersecuritynews.com · click to collapse
MATCHBOIL, a C# malware downloader linked to UAC-0099, uses command-and-control (C2) servers hidden behind Cloudflare to deliver backdoor payloads.
Its changing code shows how the group has moved from a simple downloader toward repeated server contact, stronger code hiding, and checks designed to stop security researchers from studying infections.
The observed victims were all in Ukraine. ESET recorded infections at transportation companies during July and August 2025, a manufacturing company in December 2025, and an energy company in June 2026.
These findings show continued targeting across sectors, although they do not establish the full scale of the campaign. Researchers from WeLiveSecurity documented these changes in an October 8 research report.
Their review covered samples dating from April 2024 to April 2026. CERT-UA first publicly documented MATCHBOIL in August 2025, but build timestamps suggest development began earlier. ESET assesses UAC-0099’s alignment with Russian interests with medium confidence.
The infection begins with links in targeted phishing emails. Victims download an archive containing VBScript and must manually run the script before it downloads and launches MATCHBOIL.
Earlier reporting on UAC-0099 HTA malware delivery described related attacks using fake court notices, giving readers context for the group’s document-based tricks.
.webp)
Once running, MATCHBOIL checks whether its installation directory already exists and can stop to avoid repeating an installation. It gathers device details through Windows Management Instrumentation, including processor identifiers and BIOS serial numbers.
Later versions collect additional information, such as network addresses and computer details, to identify victims during server contact.
The downloader then makes three HTTPS requests. The first receives a number, which is included in a header during the second request. Researchers believe this number may select a payload or help validate the request, but its exact purpose remains uncertain.
The second response contains HTML with a payload encoded as hexadecimal text. MATCHBOIL extracts that text using a regular expression, converts it into bytes, and writes the payload to disk.
In most cases, ESET identified the downloaded malware as MATCHWOK, a C# backdoor used by UAC-0099. The third request retrieves text that may serve as its configuration.
Cloudflare Concealment and Stronger Evasion
UAC-0099 hosts C2 servers on virtual private servers, including BitLaunch infrastructure, and uses Cloudflare to hide some servers.
ESET also observed Let’s Encrypt certificates that were not reused across domains. Similar MuddyWater cloud proxy abuse shows that hiding server addresses behind commercial services is not unique to this group.
Late-2025 versions replaced earlier Unicode-based code hiding and custom string encryption with Eziriz .NET Reactor. They also checked for debuggers and examined Windows event ID 6013 for at least three records showing two hours of system uptime.
These checks help the malware distinguish ordinary computers from analysis environments. After passing its checks, MATCHBOIL contacts C2 every two minutes instead of operating only once.
.webp)
This allows later attempts if a download fails and lets operators provide newer payloads. Fake planner and text-search windows also distract users when the malware runs without expected arguments.
An April 2026 variant, named MATCHBOIL.V2 by CERT-UA, runs as a DLL through a custom C# loader. Related Notepad++ plugin malware attacks later showed another delivery route for the updated family, while scheduled tasks remained important for maintaining access.
The updated DLL places its downloaded executable in a folder named for an SMTP client and creates a mail-themed scheduled task. This change replaces more noticeable animal-themed filenames, showing how the operators now use names that look closer to normal software.
For defenders, these changes make behavior important alongside file hashes. Teams can investigate unexpected VBScript execution, repeated HTTPS connections from unfamiliar C# programs, and newly created scheduled tasks.
Matching those events with the reported paths and network indicators offers a stronger basis for investigation than treating all Cloudflare traffic as suspicious or relying on a filename alone on affected systems.
Indicators of compromise (IoCs):-
| Filename | SHA-1 |
|---|---|
| PlannerLibrary.dll | B6569B0050B864C4A0D32326954BC2D3852A3958 |
| AnimalUpdater.exe | A926889BAB31F3C34663D18C05C4E862EF367028 |
| bootloader.exe | 026F892630D0A4FE854A75984695BA99AF0022C4 |
| PlannerAssistantManager.exe | F886B615CB9E23EAD2718FF2A61155ACFB04CE9E |
| PlannerAssistantManager.exe | 1E2C4AAC30EDFF86CD9A30BD08B199BCD3D0CCCE |
| RegularExpressionExplorer.exe | C85D28F7D272CE2BBBFB9DAE71D21BF25B8D00FC |
| HelpersLibraries.dll | 6D72B56B86FD5ED9BD188C8C88CFC69476F836E7 |
| April-2026 DLL; filename unspecified | 050926727CDD74F0B3A8A098E60B76D10FB06B14 |
| C2 domain | IP address | First seen |
|---|---|---|
virtualdailyplanner[.]pro | Not listed | 2025-11-10 |
telemetry-conf[.]com | Not listed | 2025-08-12 |
flycloud-service[.]com | 64.95.10[.]223 | 2026-03-03 |
airarticlegenerate[.]com | 64.95.13[.]210 | 2025-05-07 |
| Type | Host indicators |
|---|---|
| Directories | %LOCALAPPDATA%\DeviceMonitor; %LOCALAPPDATA%\MeowCheck; %LOCALAPPDATA%\SMTPClient |
| Payload filenames | MeowMeowProgramm.exe; SMTPClientApplication.exe; Thumbs.db |
| Supporting files | AdditionalLib.dll; config.ini; C:\Users\<username>\Pictures\WallpappersSet.jpg; C:\Users\Public\Libraries\config.library-ms |
| Mutex | Global\PlannerAssistant |
| Scheduled tasks | Updates\CheckTask; UpdateCheckers\DailyPlanner; MailClient\Checker |
| Registry value | DeviceMonitor under HKCU\Software\Microsoft\Windows\CurrentVersion\Run |
| Launch arguments | -auto; -plans; -renew |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC
Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.