Russia-Aligned UAC-0099 Evolves MATCHBOIL Malware

Written by

A Russia-aligned cyber espionage group has steadily upgraded its MATCHBOIL downloader over two years, adding stronger obfuscation, sandbox checks and changes to its execution and payload persistence.

In new research published on October 8, ESET documented MATCHBOIL versions compiled or observed between April 2024 and April 2026, finding that each version was more sophisticated than the one before it.

ESET attributed the malware to UAC-0099, a group that has targeted Ukrainian government organizations, financial institutions and media, and which ESET has assessed with medium confidence to be aligned with Russian interests.

The researchers said they had seen MATCHBOIL victims in Ukraine across transportation, manufacturing and energy, with activity observed as recently as June 2026.

MATCHBOIL was first documented by Ukraine's Computer Emergency Response Team (CERT-UA) in August 2025, but ESET found earlier samples suggesting development may have begun as early as April 2024. It is a C# downloader used to retrieve, install and establish persistence for additional payloads.

Read more on Russian state hacking in Ukraine: Fancy Bear Exploits Microsoft Office Flaw in Ukraine, EU Cyber-Attacks

Obfuscation and Sandbox Checks

Earlier MATCHBOIL versions relied on unprintable Unicode characters and string encryption to make their code harder to inspect. By late 2025, UAC-0099 had switched to the Eziriz .NET Reactor obfuscator, which can use code virtualization and control-flow obfuscation.

The later samples also introduced checks designed to determine whether MATCHBOIL was running in a sandboxed environment. ESET said these capabilities were added gradually from late 2025, indicating a shift toward making analysis and automated inspection more difficult.

The downloader's execution model also changed. Earlier samples operated as one-shot downloaders, while a version from late 2025 ran on a two-minute timer, allowing it to retrieve a newer payload from its command-and-control (C2) server.

Persistence and Continued Development

The persistence mechanism MATCHBOIL set up for its payloads changed alongside its other components. The 2024 samples combined a Windows Registry Run key value with a scheduled task, while a July 2025 version relied on Run key entries. Later samples moved back to scheduled tasks.

Late-2025 samples also introduced a daily-planner-style graphical interface, displayed when MATCHBOIL was executed manually, although the researchers noted several inconsistencies that weakened the disguise.

A February 2026 sample instead displayed a less conspicuous utility for searching text files with regular expressions, suggesting the operators had moved beyond the planner.

The activity suggests UAC-0099 has treated MATCHBOIL as an evolving component of its toolkit rather than a static downloader.

"This demonstrates a keen interest by UAC-0099 operators in improving their downloader, not only to avoid detection by security solutions, but also to use it as a key part of their toolset in future attacks," ESET concluded.

What’s Hot on Infosecurity Magazine?