Russia-aligned threat group UAC-0099 has spent the past two years steadily upgrading its C#-based MATCHBOIL downloader into a stealthy, persistent loader used in ongoing attacks against Ukrainian transportation, energy and industrial firms.[2][3][9] New research from ESET released on October 8, 2026 analyzes MATCHBOIL samples compiled between April 2024 and April 2026, concluding that each successive version is more complex than the one before it.[1][2][10]
MATCHBOIL was first publicly documented by Ukraine’s Computer Emergency Response Team (CERT-UA) in August 2025, but compilation timestamps and earlier samples uncovered by ESET show the tool had already been in development since at least April 2024.[2][3][4] Over that period, analysts observed the malware’s payload moving through different hiding places on disk—from a DeviceMonitor folder in 2024 to a whimsically named MeowCheck directory and finally to an SMTPClient folder paired with a scheduled task called Checker by April 2026.[4][10][13] ESET also reports that UAC-0099 steadily increased the downloader’s obfuscation, transitioning from simple string tricks to using the commercial .NET Reactor protector to make reverse engineering more difficult.[10][13][2]
Early MATCHBOIL builds functioned as one-shot downloaders that grabbed a single payload and exited, but newer variants maintain a persistent loop, phoning home to the command-and-control server as frequently as every two minutes to fetch updates or new modules.[10][13][1] Recent samples are delivered as DLLs executed by a custom C# loader, and include logic to detect whether they are running in virtualized or analysis environments, even checking if the operating system’s installation date is more than ten days older than the sample’s execution date and aborting accordingly.[6][2][9] In late 2025, UAC-0099 added a graphical user interface that pops up if victims manually run the payload, with decoy apps ranging from benign-looking utilities to a bizarre online cat-feeding planner intended to distract curious users while the malware installs a spying backdoor in the background.[4][7][1]
Ukrainian defenders have tracked UAC-0099 since 2022 as a Russia-aligned group repeatedly targeting government personnel and operators in the transport and energy sectors.[5][6][9] Reporting by several outlets describes the group as having links to the notorious Sandworm unit, although that attribution has not been formally confirmed by Western governments.[5][9][1] MATCHBOIL is just one component of a broader toolset that also includes the MATCHWOK backdoor and the DRAGSTARE information stealer, giving UAC-0099 the ability to download additional payloads, execute obfuscated PowerShell commands and exfiltrate sensitive files and screenshots from compromised Windows machines.[6][12][2]
To deliver MATCHBOIL and its companion tools, UAC-0099 relies heavily on phishing emails with malicious attachments as well as scripted loaders that abuse legitimate system utilities.[6][12][3] By late 2024, researchers observed the group exploiting the WinRAR vulnerability CVE-2023-38831 to achieve code execution when victims extracted booby-trapped archives, using this bug to stage a two‑phase loader that decrypted 3DES‑encrypted PowerShell code via a .NET binary.[12][15] None of the public reports on MATCHBOIL surveyed to date describe a dedicated CVE or vendor patch advisory for the loader itself, highlighting that defenders must pay attention to the actor’s delivery techniques and post‑exploitation behavior rather than waiting for traditional product updates.[2][3][4]
For defenders, the MATCHBOIL campaign offers several hunting opportunities, from unusual folder names like DeviceMonitor, MeowCheck and SMTPClient to registry Run key entries and scheduled tasks such as Checker created under custom directories like MailClient.[4][10][13] Network teams can watch for endpoints making regular outbound connections every two minutes to suspicious domains, sometimes fronted by content‑delivery services, and for HTTP requests that include custom headers derived from hardware fingerprints, such as values labeled SN.[12][1][5] Organizations that rely on WinRAR should verify that they are running patched versions that address CVE-2023-38831, and more broadly harden email gateways and endpoint controls against script‑based loaders and obfuscated .NET binaries favored by UAC-0099.[12][15][6]
Although recent MATCHBOIL activity has primarily targeted Ukrainian organizations, the group’s reliance on common enterprise software, phishing techniques and commercial obfuscation tools means its playbook could be repurposed against critical infrastructure operators elsewhere.[1][5][9] Security teams across Europe and beyond are being urged by researchers to treat MATCHBOIL as a case study in rapid malware evolution, and to assume that determined state‑aligned actors will continuously refine loaders and tradecraft to evade detection and maintain long‑term access to industrial networks.[2][8][13]
References
- Russian-aligned UAC-0099 intensifies attacks on Ukrainian industry with evolving MATCHBOIL downloader
- MATCHBOIL: New tricks, same old evil intentions – WeLiveSecurity
- Russia-Aligned UAC-0099 Evolves MATCHBOIL Malware
- What is MATCHBOIL? The Russia-aligned malware that installs a spying backdoor – Help Net Security
- Sandworm-Linked Group Sharpens Matchboil Downloader
- UAC-0099 Targets Ukrainian Government Personnel With ASHVEIN RAT Hiding Commands in HTML
- Russian hackers hide spyware behind bizarre cat-feeding planner
- Российская группа киберпреступников UAC-0099 усиливает атаки на украинские компании
- Russian-aligned spies upgrade malware used in attacks on Ukrainian transport, energy firms
- Хакеры UAC-0099 атакуют украинскую промышленность через MATCHBOIL
- UAC-0099 Tactics, Techniques, Procedures and Attack …
- ESET Deutschland GmbH: Neue Erkenntnisse zu russischer Cybersabotage zeigen Risiken für europäische Industrie
- UAC‑0099 Tactics, Techniques, Procedures and Attack …
