ESET researchers report that threat group UAC-0099 has been steadily upgrading a malware downloader called MatchBoil since 2024, using it to deliver a C# backdoor dubbed MatchWok against Ukrainian transportation, manufacturing, and energy organizations. The latest version adds stronger obfuscation, sandbox-evasion checks, and new persistence mechanisms, turning it from a one-time downloader into a dropper that can repeatedly fetch updated payloads from its command-and-control server.
darkreading.com
· 2026-10-08
ESET researchers report that the China-linked hacking group FamousSparrow has spent over a year running espionage campaigns against government agencies across Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. The group's newly identified tool, a modular C++ backdoor called SparroWocky, replaces its older SparrowDoor malware and includes advanced anti-detection and remote-control capabilities.
bleepingcomputer.com
· 2026-09-17
ESET Labs discovered that the Russia-aligned group UAC-0099 embedded a nuclear-weapon-related phrase into malicious VBScript code targeting a Ukrainian victim. The text was designed to trigger AI safety filters, causing security tools' language models to refuse analysis of the surrounding malicious code, a technique researchers are calling GuardBreaker.
darkreading.com
· 2026-09-11