Russia-Linked Group Enhances MatchBoil Malware to Target Ukrainian Organizations

Summary
ESET says UAC-0099, a group likely linked to Russian interests, is using an increasingly sophisticated MatchBoil downloader against Ukrainian organizations, delivering a backdoor and adding obfuscation, sandbox checks, and changing persistence methods.
Key points
- UAC-0099 has used MatchBoil to target Ukrainian organizations in transportation, manufacturing, and energy.
- Spear-phishing emails with links to archive files deliver a VBScript payload that users must download and run.
- MatchBoil downloads MatchWok, a C# backdoor that provides persistent access to compromised systems.
- Newer versions use .NET Reactor obfuscation and sandbox checks, making the malware harder to analyze and detect.
- Persistence methods have changed over time, including registry values, scheduled tasks, and the Windows Run key.
- By late 2025, MatchBoil was contacting its command-and-control server every two minutes to retrieve new or updated payloads.
- ESET assesses with moderate confidence that UAC-0099 is linked to Russian interests and may act as an initial access broker for Sandworm.
Article Details
- Attack Vectors
- Spear-phishing emails contain a link to an archive file with a VBScript payload; users who download and manually execute the script install MatchBoil.
- MatchBoil repeatedly contacts its command-and-control server to retrieve new or updated payloads, including MatchWok.
MITRE ATT&CK
T1027 · Obfuscated Files or InformationMatchBoil uses obfuscation, including Unicode-based obfuscation and Eziriz .NET Reactor, to make analysis and detection harder.T1053.005 · Scheduled TaskMatchBoil versions used scheduled tasks to maintain persistence on compromised systems.T1059.005 · Visual BasicThe archive contains a VBScript payload that users manually execute to install MatchBoil.T1082 · System Information DiscoveryMatchBoil obtains details about the victim's machine for identification during subsequent command-and-control communications.T1105 · Ingress Tool TransferMatchBoil downloads additional and updated payloads from its command-and-control server.T1204.002 · Malicious FileUsers who download and manually execute the VBScript payload from the archive install MatchBoil.T1497.001 · System ChecksNewer MatchBoil versions perform sandbox checks.T1547.001 · Registry Run Keys / Startup FolderSome MatchBoil versions use the Windows Run key to launch the malware when a user logs in.T1566.002 · Spearphishing LinkUAC-0099's attacks typically begin with spear-phishing emails containing a link to an archive file.
Threat Actors
SandwormESET assesses that UAC-0099 is likely an initial access broker for Sandworm, which the article links to Russia's military intelligence agency and describes as responsible for destructive attacks on Ukrainian infrastructure.UAC-0099ESET tracks the group as UAC-0099 and assesses with moderate confidence that it is linked to Russian interests. ESET considers it likely to be an initial access broker for Sandworm.
Malware
MatchBoilAccording to ESET, the group, tracked as UAC-0099, is using the downloader, dubbed MatchBoil, to deliver MatchWok, a C# backdoor that gives the attacker persistent access to compromised systems.MatchWokAccording to ESET, the group, tracked as UAC-0099, is using the downloader, dubbed MatchBoil, to deliver MatchWok, a C# backdoor that gives the attacker persistent access to compromised systems.
Vendors
Products
Tools
Countries
RussiaA likely Russia-affiliated cyber-espionage group is using an increasingly sophisticated malware downloader to target Ukrainian organizations across the transportation, manufacturing, and energy sectors.Ukrainelinked to Russia's military intelligence agency and responsible for numerous destructive attacks on Ukraine's power grid and other infrastructure. In the MatchBoil campaign, UAC-0099 initially targeted
Industries
EnergyA likely Russia-affiliated cyber-espionage group is using an increasingly sophisticated malware downloader to target Ukrainian organizations across the transportation, manufacturing, and energy sectors.ManufacturingA likely Russia-affiliated cyber-espionage group is using an increasingly sophisticated malware downloader to target Ukrainian organizations across the transportation, manufacturing, and energy sectors.TransportationA likely Russia-affiliated cyber-espionage group is using an increasingly sophisticated malware downloader to target Ukrainian organizations across the transportation, manufacturing, and energy sectors.