ESET: UAC-0099 refines MatchBoil malware to hit Ukrainian critical sectors
ESET researchers report that threat group UAC-0099 has been steadily upgrading a malware downloader called MatchBoil since 2024, using it to deliver a C# backdoor dubbed MatchWok against Ukrainian transportation, manufacturing, and energy organizations. The latest version adds stronger obfuscation, sandbox-evasion checks, and new persistence mechanisms, turning it from a one-time downloader into a dropper that can repeatedly fetch updated payloads from its command-and-control server.
GoKawiil's interpretation of the reporting above, not reported fact.
ESET assesses with moderate confidence that UAC-0099 is linked to Russian interests, based largely on its focus on Ukrainian targets, and suggests it may act as an initial access broker for Sandworm, the Russian military intelligence-linked group tied to attacks on Ukraine's power grid. The malware's continuous refinement indicates the group is investing in evading detection and building a durable toolset, which could signal preparation for further intrusions into critical infrastructure.
- MatchBoil downloader has been iteratively upgraded by UAC-0099 since 2024, adding obfuscation and sandbox checks.
- It now delivers a persistent C# backdoor called MatchWok to Ukrainian transportation, manufacturing, and energy organizations.
- ESET links UAC-0099 with moderate confidence to Russian interests and possible ties to the Sandworm group.
Source: darkreading.com — Jai Vijayan, 2026-10-08
Published there as: “Russian Spies Give 'MatchBoil' Malware a Stealthy Facelift”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.