Oct 8 / Latest News

ESET Tracks Two Years of MATCHBOIL Malware Evolution in UAC‑0099 Attacks Against Ukraine

ESET researchers traced nearly two years of development in MATCHBOIL, a downloader used by the Russia‑aligned threat group UAC‑0099 to deploy a second‑stage espionage tool on Windows systems in Ukraine. Victims included transportation companies in mid‑2025, a manufacturer later that year, and an energy company in June 2026.

MATCHBOIL delivers MATCHWOK, a C# backdoor capable of taking screenshots, executing PowerShell commands, and performing other spying functions. The infection chain begins with a spear‑phishing link that downloads an archive containing a VBScript file, which retrieves and launches MATCHBOIL. The malware fingerprints the machine using CPU ID and BIOS serial number, then makes three HTTPS requests to the group’s server. The payload arrives hidden as hex‑encoded text inside an HTML response, which MATCHBOIL extracts and writes to a folder under %LOCALAPPDATA% before establishing persistence via scheduled tasks or registry keys.

The payload’s hiding location changed over time. Early samples stored it in a folder named DeviceMonitor. By late 2025 it appeared as MeowMeowProgramm.exe under MeowCheck, and by April 2026 it was SMTPClientApplication.exe under SMTPClient, with a scheduled task named Checker in a MailClient directory. Later versions also ran on a two‑minute timer to avoid losing access if the first server contact failed. MATCHBOIL replaced its custom string scrambling with the commercial obfuscator Eziriz .NET Reactor, which virtualizes code and complicates analysis.

Sandbox evasion techniques evolved as well. MATCHBOIL checks Windows event logs for system uptime in both English and Russian, requiring at least three events showing two hours or more. The April 2026 variant added a second test, verifying that the operating system was installed at least ten days before execution. Decoy windows became less polished over time, with late‑2025 builds displaying a daily planner featuring a cat photo and mislabeled text fields.

UAC‑0099 has historically targeted government, financial, and media organizations in Ukraine, but the transport, manufacturing, and energy victims represent an expanded profile. ESET notes that UAC‑0099 acts as an initial access broker for Sandworm, another Russia‑aligned APT group responsible for severe harm and disruptive cyber operations, suggesting MATCHBOIL infections may support broader campaigns.

Ukraine’s CERT‑UA documented MATCHBOIL in August 2025, with compilation timestamps pointing to mid‑2024—indicating the malware likely operated for a year before public reporting. UAC‑0099 rents virtual servers from providers such as BitLaunch and hides infrastructure behind Cloudflare, with Let’s Encrypt certificates that are not reused across domains.