A Russia-aligned cyber-espionage actor known as UAC-0099 is refining a malware dropper called MatchBoil to target Ukrainian organisations across the transportation, manufacturing and energy sectors. ESET's analysis identifies MatchBoil as the delivery vehicle for MatchWok, a C# backdoor that provides attackers with persistent access to compromised machines.
The group has been developing MatchBoil since at least 2024, with each iteration bringing stronger obfuscation, sandbox detection and evolving persistence mechanisms.
The campaign typically begins with spear-phishing emails containing a link to an archive carrying a VBScript payload. Once executed, MatchBoil checks for a specific directory and terminates if it is present, then gathers machine details to identify victims during subsequent command-and-control communications. Over time, MatchBoil has shifted from a one-shot downloader to a dropper capable of repeatedly retrieving updated payloads from its C2 server.
Recent samples show use of the .NET Reactor obfuscator, sandbox checks and a more discreet user interface to hinder analysis. Persistence has also evolved: earlier methods used a registry value and scheduled tasks, while later versions rely on the Windows Run key and, intermittently, scheduled tasks. By late 2025, the malware was capable of executing every two minutes to re-establish contact with the C2 and fetch new payloads, underscoring the operators’ aim to sustain access for future operations.