Russian-aligned UAC-0099 intensifies attacks on Ukrainian industry with evolving MATCHBOIL downloader

GlobeNewswire | ESET
Today at 9:00am UTC
  • ESET Research investigates MATCHBOIL, a C# downloader used by the Russia-aligned group UAC-0099 to download, install, and persist additional payload.
  • Victims that ESET has seen in its telemetry were in Ukraine, across various sectors.
  • The analyzed MATCHBOIL versions show a change in code, now employing .NET Reactor obfuscator.
  • Although MATCHBOIL was first documented by CERT-UA in August 2025, based on the compilation of timestamps of some discovered samples, ESET believes that MATCHBOIL could have been in development since April 2024.

MONTREAL and BRATISLAVA, Slovakia, Oct. 08, 2026 (GLOBE NEWSWIRE) -- ESET researchers have documented the evolution of the MATCHBOIL malware, a custom C# downloader wielded by the Russia-aligned UAC-0099 APT group. The malware is used to download a payload from the group’s C&C server, install it, and establish its persistence. Although MATCHBOIL was first documented by CERT-UA in August 2025, ESET research indicates that it has been in development since at least 2024. The earliest versions of the malware that ESET Research analyzed are from April 2024 and the latest are from April 2026; each new iteration of the downloader is more sophisticated than the last. All victims of MACTHBOIL’s cyberespionage that ESET has seen in its telemetry were in Ukraine, across various sectors.

From July to August 2025, ESET saw samples of the downloader at multiple transportation companies. In December of the same year, they were seen at a manufacturing company. Later, in June 2026, ESET telemetry registered further MATCHBOIL samples, this time at a company in the energy sector.

ESET Research’s investigation of MATCHBOIL samples from April 2024 to April 2026 revealed multiple modifications, from code-level structure to the use of the .NET Reactor obfuscator, all of which were implemented in a relatively short time. This demonstrates a keen interest by UAC-0099 operators in improving their downloader, not only to avoid detection by security solutions, but also to use it as a key part of their toolset in future attacks.

“The malware is distributed via malicious links in spear phishing emails. Clicking the link downloads an archive file with a VBScript file payload that downloads and executes MATCHBOIL on the victim machine. MATCHBOIL has evolved from a one-shot downloader to a downloader that can communicate with the C&C server every two minutes; in late 2025, UAC-0099 added a graphical user interface that appears if the user executes the payload. It changed to a less-conspicuous version in early 2026,” says ESET researcher Fernando Tavella, who analyzed MATCHBOIL.

UAC-0099 uses virtual private servers such as BitLaunch to host its C&C servers, and cloud services such as Cloudflare to hide them. These servers both use HTTP and HTTPS.

UAC-0099 is a cyberespionage group targeting governmental organizations, financial institutions, and media, all in Ukraine. Based on the targeting, ESET believes with medium confidence that the group is aligned with Russian interests. ESET believes that UAC-0099 can act as an initial access broker for Sandworm, another Russia-aligned group best known for its destructive attacks in Ukraine.

For a more detailed and technical analysis of MATCHBOIL, check out the ESET Research blogpost, “MATCHBOIL: New tricks, same old evil intentions,” on WeLiveSecurity.com. Make sure to follow ESET Research on Twitter (today known as X), BlueSky, and Mastodon for the latest news from ESET Research.

About ESET® 

ESET protects organizations, critical infrastructure, and individuals, helping them build digital resilience and confidence in an increasingly AI-driven world. With more than 35 years of cybersecurity expertise, over 25 years of AI innovation, and 11 global R&D centers, ESET develops proprietary technologies designed to protect against evolving cyber threats and secure the broader AI ecosystem. Grounded in scientific rigor and taking a preemptive approach to security, ESET delivers effortless protection that remains under expert human oversight. Headquartered in the European Union and privately owned, ESET protects millions of users and more than 500,000 organizations across 178 countries. Committed to responsible AI and customer trust, ESET protects the progress that technology enables. For more information, visit www.eset.com or follow ESET’s social media, podcasts, and blogs. 


Media contact:

Jessica Beffa

jessica.beffa@eset.com

720-413-4938

Primary Logo