www.darkreading.com 8 Oct 2026, 18:01 UTC

Russia Aligned Hackers Refine MatchBoil Malware to Spy on Ukraine’s Key Sectors

Russia Aligned Hackers Refine MatchBoil Malware to Spy on Ukraine’s Key Sectors
CyberSIXT Evidence Panel
Threat Actor

A Russia-aligned cyber-espionage actor known as UAC-0099 is refining a malware dropper called MatchBoil to target Ukrainian organisations across the transportation, manufacturing and energy sectors. ESET's analysis identifies MatchBoil as the delivery vehicle for MatchWok, a C# backdoor that provides attackers with persistent access to compromised machines.

The group has been developing MatchBoil since at least 2024, with each iteration bringing stronger obfuscation, sandbox detection and evolving persistence mechanisms.

The campaign typically begins with spear-phishing emails containing a link to an archive carrying a VBScript payload. Once executed, MatchBoil checks for a specific directory and terminates if it is present, then gathers machine details to identify victims during subsequent command-and-control communications. Over time, MatchBoil has shifted from a one-shot downloader to a dropper capable of repeatedly retrieving updated payloads from its C2 server.

Recent samples show use of the .NET Reactor obfuscator, sandbox checks and a more discreet user interface to hinder analysis. Persistence has also evolved: earlier methods used a registry value and scheduled tasks, while later versions rely on the Windows Run key and, intermittently, scheduled tasks. By late 2025, the malware was capable of executing every two minutes to re-establish contact with the C2 and fetch new payloads, underscoring the operators’ aim to sustain access for future operations.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline