UAC-0099 upgrades MATCHBOIL in Ukrainian espionage campaigns
ESET says Russia-aligned UAC-0099 used MATCHBOIL through April 2026 to plant MATCHWOK on Ukrainian transport, manufacturing, and energy firms.
ESET research published 8 October 2026 details MATCHBOIL, a custom C# downloader that UAC-0099 — active since at least 2022 and assessed with medium confidence as Russia-aligned — uses to install and persist a follow-on payload, usually the MATCHWOK espionage backdoor, which can capture screenshots and run PowerShell. Wording differs: The Record calls the group “likely” aligned with Russian interests and dates development to at least July 2024, while ESET-based accounts cite builds from April 2024 through April 2026 and call MATCHBOIL a downloader; Dark Reading calls UAC-0099 Russian-linked and MatchBoil a dropper. Spearphishing leads the victim to run a VBScript; ESET says the link delivers an archive, after which MATCHBOIL fingerprints the host, makes three HTTPS requests, extracts a hex-encoded payload, and persists it with a scheduled task or Registry Run key, whereas Help Net Security says the script downloads MATCHBOIL. Later samples, including an April 2026 MATCHBOIL.V2 DLL that Cyber Security News says CERT-UA named and that GBHackers says ships with a custom loader and installs SMTPClientApplication.exe, added Eziriz .NET Reactor obfuscation after Unicode renaming, sandbox checks, two-minute C2 polling, and decoy GUIs such as a daily planner. Those checks are described differently — Help Net Security says uptime and whether Windows was installed ten days earlier, while GBHackers cites Windows event ID 6013 and Debugger.IsAttached — with persistence via a seven-minute DailyPlanner task and MailClient\Checker, and C2 on VPS behind Cloudflare using Let’s Encrypt, including virtualdailyplanner[.]pro and telemetry-conf[.]com. Every observed infection was in Ukraine: transportation firms in July–August 2025 (ESET says mid-2025), a manufacturer in December 2025, and an energy company in June 2026, though Infosecurity’s blurb also names government targets and GBHackers says the group targets government, financial, and media organizations; UAC-0099 has brokered access for Sandworm, deploys LONEPAGE, and CERT-UA previously tied its court-summons phishing to MATCHWOK and Dragstare.
- MATCHBOIL is a custom C# downloader (Dark Reading calls it a dropper) used by UAC-0099, active since at least 2022, to install and persist MATCHWOK, a C# espionage backdoor that can take screenshots and run PowerShell.
- ESET cites builds from April 2024 through April 2026; The Record says development since at least July 2024. Cyber Security News says CERT-UA names the April 2026 DLL variant MATCHBOIL.V2.
- Alignment wording differs: ESET and several outlets say medium-confidence Russia-aligned; The Record says “likely” aligned with Russian interests; Dark Reading says Russian-linked.
- Every observed MATCHBOIL infection was in Ukraine: transportation firms in July and August 2025 (ESET’s write-up says mid-2025), a manufacturer in December 2025, and an energy company in June 2026.
- Delivery is spearphishing that leads a victim to run a VBScript; ESET says the link delivers an archive, while Help Net Security says the script downloads MATCHBOIL. It then makes three HTTPS requests and extracts a hex-encoded payload.
- Later builds moved from Unicode renaming to Eziriz .NET Reactor, added sandbox checks, a two-minute C2 poll, and decoy GUIs. Help Net Security cites an uptime and ten-day Windows-install check; GBHackers cites event ID 6013 and…
- GBHackers: V2 uses a custom loader, installs SMTPClientApplication.exe, and persists via DailyPlanner (every seven minutes) and MailClient\Checker; C2 is on VPS behind Cloudflare with Let’s Encrypt, including virtualdailyplanner[.]pro and…
- UAC-0099 has brokered access for Sandworm and deploys LONEPAGE. Sector claims differ: MATCHBOIL victims are transport, manufacturing, and energy, while some outlets also tie the group to government, financial, and media targets. CERT-UA…
Coverage timelineoldest first · each row is one article
- · 1d agoMATCHBOIL: New tricks, same old evil intentions
ESET WeLiveSecurity· 67
ESET details MATCHBOIL, a C# downloader UAC-0099 uses against Ukrainian transport, manufacturing, and energy firms.
- · 1d agoWhat is MATCHBOIL? The Russia-aligned malware that installs a spying backdoor
Help Net Security· 76
Russia-aligned UAC-0099 uses MATCHBOIL to install the MATCHWOK spy backdoor on Ukrainian transport, manufacturing, and energy firms.
- · 22h ago