ESET: UAC-0099 refines MatchBoil malware to hit Ukrainian critical sectors
ESET researchers report that threat group UAC-0099 has been steadily upgrading a malware downloader called MatchBoil since 2024, using it to deliver a C# backdoor dubbed MatchWok against Ukrainian transportation, manufacturing, and energy organizations. The latest version adds stronger obfuscation, sandbox-evasion checks, and new persistence mechanisms, turning it from a one-time downloader into a dropper that can repeatedly fetch updated payloads from its command-and-control server.