Threats & Adversaries

UAC-0099 keeps MATCHBOIL alive in Ukraine

ESET says the Russia-aligned UAC-0099 group has spent almost two years evolving MATCHBOIL, a downloader that has reached Ukrainian transportation firms in 2025, a manufacturer in December 2025, and an energy company in June 2026. The chain starts with a spearphishing link that pulls down an archive, then a VBScript file that launches the malware.

MATCHBOIL makes the server hand back HTML with the payload hidden as hex text, then unwraps it on the victim machine and drops MATCHWOK, a C# backdoor that can take screenshots and run PowerShell. It also adds persistence with a scheduled task or registry key, while timers, obfuscation, and sandbox checks make cleanup and analysis harder.

For defenders in Ukraine-linked transportation, manufacturing, and energy environments, this looks less like a one-off drop than a durable espionage foothold. The access may outlast the first infection and can also be reused by others if the downloader is allowed to keep working.

2 sources · 5h ago

Timeline

Sources

Part of the PlainSec briefing for 2026-10-08

Every edition of this story: UAC-0099 keeps MATCHBOIL alive in Ukraine

More from today