UAC-0099 upgrades MATCHBOIL in Ukrainian espionage campaigns
ESET says Russia-aligned UAC-0099 upgraded MATCHBOIL to install MATCHWOK on Ukrainian transport, manufacturing, and energy firms through June 2026.
ESET research published October 8, 2026 says UAC-0099 has used and upgraded MATCHBOIL, a C# downloader, to install the MATCHWOK espionage backdoor on Windows systems in Ukraine. Help Net Security and Infosecurity Magazine assess the group as Russia-aligned with medium confidence, while The Record says it is likely aligned with Russian interests and Dark Reading describes it as Russian-linked. Delivery is by phishing or spear-phishing links that run a VBScript launching MATCHBOIL, which fingerprints the host, fetches a hex-encoded payload over HTTPS, and persists through a scheduled task or Registry Run key. Later samples added Eziriz .NET Reactor obfuscation, sandbox checks, a two-minute C2 timer, and decoy interfaces; an April 2026 build also checks uptime and whether Windows was installed ten days earlier. Sources agree observed victims were Ukrainian transport, manufacturing, and energy organizations, with infections dated July–August 2025, December 2025, and June 2026, though Infosecurity Magazine's tldr also names the government sector. Development timing differs: versions from April 2024 to April 2026, development since at least July 2024, or nearly two years of use. The Record adds a prior CERT-UA link to MatchWok and Dragstare, and Help Net Security says UAC-0099 has brokered access for Sandworm.
- ESET research published Oct. 8, 2026 describes UAC-0099 as Russia-aligned with medium confidence; The Record says "likely aligned with Russian interests," and Dark Reading calls the group Russian-linked.
- MATCHBOIL (also MatchBoil) is a C# downloader—Dark Reading calls it a dropper—used to install MATCHWOK (MatchWok), a C# espionage backdoor that can take screenshots and run PowerShell.
- Infosecurity Magazine reports MATCHBOIL versions from April 2024 to April 2026; The Record says development since at least July 2024; Help Net Security says nearly two years of use, including an April 2026 build that checks uptime and…
- Spear-phishing links deliver a VBScript that launches MATCHBOIL, which fingerprints the host, retrieves a hex-encoded payload over HTTPS, and persists via a scheduled task or Windows Registry Run key.
- Late-2025 samples added Eziriz .NET Reactor obfuscation, sandbox-evasion checks, a two-minute C2 polling timer, and decoy GUIs such as a daily planner.
- ESET telemetry showed only Ukrainian victims: transportation firms in July and August 2025, a manufacturer in December 2025, and an energy company in June 2026; Infosecurity Magazine's tldr also cites the government sector.
- Help Net Security says UAC-0099 has brokered initial access for Russia-aligned Sandworm; The Record says CERT-UA previously tied the group's court-summons phishing to MatchWok and the Dragstare stealer.
Coverage timelineoldest first · each row is one article
- · 14h agoWhat is MATCHBOIL? The Russia-aligned malware that installs a spying backdoor
Help Net Security· 76
Russia-aligned UAC-0099 uses MATCHBOIL to install the MATCHWOK spy backdoor on Ukrainian transport, manufacturing, and energy firms.
- · 11h agoRussian-aligned spies upgrade malware used in attacks on Ukrainian transport, energy firms
The Record· 74
UAC-0099 upgraded MatchBoil malware in espionage attacks on Ukrainian transport and energy firms.
- · 10h agoRussia-Aligned UAC-0099 Evolves MATCHBOIL Malware
Infosecurity Magazine· 55