Executive Summary
Since at least April 2024, the Russia-aligned cyber espionage group UAC-0099 has been actively developing and refining MATCHBOIL, a custom C# downloader. Primarily targeting Ukrainian government organizations, media, and critical infrastructure, the group has significantly increased the malware's sophistication. Recent versions observed in 2026 incorporate advanced obfuscation through Eziriz .NET Reactor and specialized sandbox evasion techniques designed to identify analysis environments by checking system uptime and installation dates.
The attack chain typically begins with spearphishing emails containing malicious links that deliver VBScript payloads. These scripts subsequently execute MATCHBOIL to download, install, and persist secondary backdoors such as MATCHWOK. The group's evolution from one-shot downloaders to persistent, timer-based execution models demonstrates a shift toward maintaining long-term access. Given UAC-0099's role as a suspected initial access broker for Sandworm, these developments pose a high risk of destructive follow-on attacks against Ukrainian interests.
Defense teams should focus on monitoring for unauthorized WMI queries, unexpected scheduled tasks, and the specific registry run keys used for persistence. The transition to masquerading as legitimate daily planners or text utilities indicates a continued focus on social engineering and deceptive user interfaces to bypass manual scrutiny.
Key Details
Threat Name
MATCHBOIL
Affects
—
Adversary
UAC-0099 Other Adversaries and Aliases: Sandworm
MITRE Techniques
Malware/Tools
MATCHBOIL, MATCHWOK, LONEPAGE, THUMBCHOP, CLOGFLAG, SEAGLOW, OVERJAM
