Russia-Linked Group Enhances MatchBoil Malware to Target Ukrainian Organizations

· Original article ↗

Summary

ESET says UAC-0099, a group likely linked to Russian interests, is using an increasingly sophisticated MatchBoil downloader against Ukrainian organizations, delivering a backdoor and adding obfuscation, sandbox checks, and changing persistence methods.

Key points

  • UAC-0099 has used MatchBoil to target Ukrainian organizations in transportation, manufacturing, and energy.
  • Spear-phishing emails with links to archive files deliver a VBScript payload that users must download and run.
  • MatchBoil downloads MatchWok, a C# backdoor that provides persistent access to compromised systems.
  • Newer versions use .NET Reactor obfuscation and sandbox checks, making the malware harder to analyze and detect.
  • Persistence methods have changed over time, including registry values, scheduled tasks, and the Windows Run key.
  • By late 2025, MatchBoil was contacting its command-and-control server every two minutes to retrieve new or updated payloads.
  • ESET assesses with moderate confidence that UAC-0099 is linked to Russian interests and may act as an initial access broker for Sandworm.

Article Details

Attack Vectors
  • Spear-phishing emails contain a link to an archive file with a VBScript payload; users who download and manually execute the script install MatchBoil.
  • MatchBoil repeatedly contacts its command-and-control server to retrieve new or updated payloads, including MatchWok.

MITRE ATT&CK

Threat Actors

Malware

Vendors

Products

Tools

Countries

Industries

Related Articles