Russian Spies Give ‘MatchBoil’ Malware a Stealthy Facelift
Cyber-espionage actor UAC-0099 has been steadily refining its flagship dropper in campaigns targeting Ukrainian organizations.
Cyber-espionage actor UAC-0099 has been steadily refining its flagship dropper in campaigns targeting Ukrainian organizations.
A likely Russia-affiliated cyber-espionage group is using an increasingly sophisticated malware downloader to target Ukrainian organizations across the transportation, manufacturing, and energy sectors.
According to ESET, the group, tracked as UAC-0099, is using the downloader, dubbed MatchBoil, to deliver MatchWok, a C# backdoor that gives the attacker persistent access to compromised systems.
The security vendor’s analysis showed that MatchBoil has been in active development since at least 2024, and has kept steadily improving with every iteration since then. Though its core function remains the same — to download additional payloads — the latest edition of the malware features stronger obfuscation, sandbox checks, and evolving persistence mechanisms, researchers warn.
A Constantly Evolving Malware Strain
Overall, MatchBoil has evolved from what ESET terms a “one-shot downloader” into a dropper capable of repeatedly retrieving updated payloads from its command-and-control (C2) server.
“Our investigation of MatchBoil samples from April 2024 to April 2026 revealed multiple modifications, from code-level structure to the use of the .NET Reactor obfuscator, all of these implemented in a relatively short time,” ESET said in a technical report this week. “This demonstrates a keen interest by UAC-0099 operators in improving their downloader, not only to avoid detection by security solutions, but also to use it as a key part of their toolset in future attacks.”
Russia-Aligned Cyber Espionage?
UAC-0099 is a threat actor operating since 2023, which ESET believes with moderate confidence is linked to Russian interests, primarily because it targets Ukrainian organizations. The security vendor also thinks it’s likely that UAC-0099 is an initial access broker for Sandworm, the threat actor linked to Russia’s military intelligence agency and responsible for numerous destructive attacks on Ukraine’s power grid and other infrastructure. In the MatchBoil campaign, UAC-0099 initially targeted transportation companies before expanding its focus to manufacturing and, more recently, the energy sector.
The threat actor’s attacks typically have begun with spear-phishing emails containing a link to an archive file with a VBScript payload. Users tricked into downloading and manually executing the script end up with MatchBoil on their systems. Once running, the malware checks for the presence of a specific directory on the victim’s machine and terminates if the directory already exists, according to ESET. The malware then obtains specific details about the machine, which it uses to identify the victim during subsequent C2 communications.
MatchBoil: New & Improved Malware Capabilities
Samples of the malware that ESET examined showed UAC-0099 steadily refining MatchBoil to make it harder for defenders to detect and analyze. While the 2024 versions, for instance, relied on relatively basic Unicode-based obfuscation, the 2026 edition uses Eziriz .NET Reactor, a commercial .NET obfuscation and protection tool for making an application’s code harder to reverse engineer and analyze. Similarly, newer versions of the malware include sandbox checks and a less conspicuous interface designed to avoid detection by security researchers and users.
UAC-0099 has also been constantly tinkering with MatchBoil’s persistence mechanisms, too, ESET noted. Initial versions of the malware used both a registry value and a scheduled task to maintain persistence on compromised systems and ensure the payload would continue to run on them, even through system reboots. Later versions switched to the Windows Run key exclusively to launch the malware when a user logged in to the system. Last year, the malware authors went back to using scheduled tasks as a persistence mechanism.
ESET found that by late 2025, MatchBoil had evolved from a dropper that essentially ran once, contacted its C2 server, and downloaded and installed a next-stage payload, into one that executed every two minutes. The change allowed it to repeatedly contact its control server and retrieve new or updated payloads.
“From all the samples of the downloader that we collected, we see that UAC‑0099 is continually improving MatchBoil for future attacks,” ESET concluded. “The samples compiled or seen before November 2025 were much more straightforward and simple to analyze compared to newer ones.”