A Russia-aligned cyber espionage group known as UAC-0099 has been steadily evolving its MATCHBOIL downloader over a two-year period, according to ESET research published on 8 October 2026. The analysis covers MATCHBOIL samples observed between April 2024 and April 2026, showing a progression from simpler obfuscation to more sophisticated techniques, including the use of the Eziriz .NET Reactor obfuscator with code virtualization and control-flow obfuscation.
Later revisions also added sandbox-detection checks to hinder automated analysis, and altered the downloader’s execution model from a one-shot launcher to a two-minute timer that fetches a newer payload from its C2 server.
In terms of persistence and deployment, MATCHBOIL has shown a pattern of evolving its ability to establish and refresh access to additional payloads. Early samples used a Windows Registry Run key value plus a scheduled task, with July 2025 drifting to Run key entries alone, and later versions returning to scheduled tasks. By late 2025, the toolkit featured a daily-planner style graphical interface when run manually, though inconsistencies in the disguise weakened the appearance.
A February 2026 sample instead presented a more benign utility for searching text files with regular expressions, suggesting operators were broadening MATCHBOIL’s functionality within their toolkit. ESET notes that UAC-0099 appears to treat MATCHBOIL as an evolving component rather than a static downloader, reinforcing its role as a developing element in broader attack campaigns. Victims have been observed in Ukraine across transportation, manufacturing and energy sectors, with activity dated as recently as June 2026.