What is MATCHBOIL? The Russia-aligned malware that installs a spying backdoor
Russia-aligned UAC-0099 uses MATCHBOIL to install the MATCHWOK spy backdoor on Ukrainian transport, manufacturing, and energy firms.
ESET says Russia-aligned group UAC-0099 has used the MATCHBOIL downloader for nearly two years to install MATCHWOK, a C# espionage backdoor, on Windows systems in Ukraine. Telemetry shows only Ukrainian victims: transportation companies in July and August 2025, a manufacturer in December 2025, and an energy company in June 2026. A spear-phishing link delivers a VBScript that launches MATCHBOIL, which fingerprints the host, retrieves a hex-encoded payload over HTTPS, and persists it with a scheduled task or registry key. MATCHWOK can take screenshots and run PowerShell; ESET says UAC-0099 has brokered initial access for Sandworm and assigns medium-confidence Russian alignment.
- All ESET victims were Ukrainian transport, manufacturing, or energy organizations.
- Spear-phishing links deliver a VBScript that downloads MATCHBOIL.
- MATCHWOK captures screenshots and executes PowerShell on the host.
- UAC-0099 has brokered initial access for Russia-aligned Sandworm.
- April 2026 build checks uptime and whether Windows was installed ten days earlier.
Full article664 words · extracted from helpnetsecurity.com · click to collapse
ESET researchers traced almost two years of changes to MATCHBOIL, a downloader that the Russia-aligned group UAC-0099 uses to plant a second program on Windows machines in Ukraine.

GUI displayed at MATCHBOIL’s runtime (Source: ESET)
Every victim in ESET’s telemetry was in Ukraine: transportation companies in July and August 2025, a manufacturer in December 2025, and an energy company in June 2026. The program MATCHBOIL installs is a spying tool, and the access it creates may be useful to other groups.
What MATCHBOIL installs
“We have seen in ESET telemetry that MATCHBOIL downloads a payload known as MATCHWOK, a C# backdoor with capabilities for espionage on the victim’s machine. For example, it can take screenshots of the victim desktop or execute PowerShell commands on the victim’s computer,” ESET researcher Fernando Tavella, told Help Net Security.
The delivery chain starts with a link in a spear phishing email. The link downloads an archive holding a VBScript file, which downloads and runs MATCHBOIL. The malware fingerprints the machine using its CPU ID and BIOS serial number, then makes three HTTPS requests to the group’s server. The second response is HTML with the payload hidden inside as hex-encoded text, and MATCHBOIL pulls it out, writes it to a folder under %LOCALAPPDATA%, and sets it to relaunch through a scheduled task or a Windows registry key. If that folder already exists, MATCHBOIL exits.
What changed
The payload’s hiding place moved over time. In 2024 it lived in a folder called DeviceMonitor. By late 2025 it was MeowMeowProgramm.exe in a folder called MeowCheck, and by April 2026 it was SMTPClientApplication.exe in a folder called SMTPClient, with a scheduled task named Checker under a directory named MailClient. If you are hunting on a machine, those are the names to search for.
The early versions ran once and relied on the persistence setting to do the rest. By late 2025 MATCHBOIL ran on a two-minute timer, so a failed first contact with the server no longer ended the infection. It also swapped its homemade string scrambling for a commercial obfuscator, Eziriz .NET Reactor, which can virtualize code and tangle its control flow.
The sandbox checks arrived at the same time. MATCHBOIL reads Windows event logs for system uptime, searching in English and in Russian, and decides it is not in a sandbox only if it finds at least three events showing 7,200 seconds (two hours) or more. The April 2026 version added a second test: it checks whether the operating system was installed at least ten days before the malware runs.
The decoys are less polished. Late 2025 builds show a daily planner with a cat photo to anyone who launches them by hand. The window is titled “Dairy,” and both text boxes are labeled “Today.”
Why these targets
UAC-0099 has been described as going after government bodies, financial institutions, and media in Ukraine, so the transport, manufacturing, and energy victims are new. Asked whether that signals a wider target list, Tavella pointed to the group’s history:
“UAC-0099 has been targeting different entities in Ukraine. We believe that the group has different interests and their expansion in the victimology could mean that they are seeking to maximise their impact in UA. Let’s remember that this group has been an initial access broker of Sandworm, another Russia-aligned APT group, so it is possible they are seeking victims that can be of interest for other APT groups that UAC-0099 can assist.”
An initial access broker breaks into networks and hands that foothold to someone else. ESET attributes the group to Russian interests with medium confidence, based on its targeting.
Ukraine’s CERT-UA documented MATCHBOIL in August 2025. Compilation timestamps in those samples point to mid-2024, which means the tool likely ran for about a year before anyone published on it.
UAC-0099 rents virtual servers from providers such as BitLaunch and puts Cloudflare in front of them. ESET found that its Let’s Encrypt certificates are not reused across domains.

Download eBook: Identity-First Threat Intelligence