www.infosecurity-magazine.com 8 Oct 2026, 13:00 UTC

Russia Aligned UAC-0099 Refines MATCHBOIL Malware to Target Ukraine

CyberSIXT Evidence Panel
Threat Actor

A Russia-aligned cyber espionage group known as UAC-0099 has been steadily evolving its MATCHBOIL downloader over a two-year period, according to ESET research published on 8 October 2026. The analysis covers MATCHBOIL samples observed between April 2024 and April 2026, showing a progression from simpler obfuscation to more sophisticated techniques, including the use of the Eziriz .NET Reactor obfuscator with code virtualization and control-flow obfuscation.

Later revisions also added sandbox-detection checks to hinder automated analysis, and altered the downloader’s execution model from a one-shot launcher to a two-minute timer that fetches a newer payload from its C2 server.

In terms of persistence and deployment, MATCHBOIL has shown a pattern of evolving its ability to establish and refresh access to additional payloads. Early samples used a Windows Registry Run key value plus a scheduled task, with July 2025 drifting to Run key entries alone, and later versions returning to scheduled tasks. By late 2025, the toolkit featured a daily-planner style graphical interface when run manually, though inconsistencies in the disguise weakened the appearance.

A February 2026 sample instead presented a more benign utility for searching text files with regular expressions, suggesting operators were broadening MATCHBOIL’s functionality within their toolkit. ESET notes that UAC-0099 appears to treat MATCHBOIL as an evolving component rather than a static downloader, reinforcing its role as a developing element in broader attack campaigns. Victims have been observed in Ukraine across transportation, manufacturing and energy sectors, with activity dated as recently as June 2026.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline