Russia-Aligned Hackers Spent Two Years Upgrading Their MATCHBOIL Malware
A Russia-aligned cyber espionage group has spent two years improving a piece of malware called MATCHBOIL. In research published on October 8, security firm ESET documented versions compiled or observed between April 2024 and April 2026, and found that each one was more sophisticated than the last. ESET attributed the malware to UAC-0099, a group that has targeted Ukrainian government bodies, financial institutions and media, and assessed with medium confidence that it is aligned with Russian interests.
MATCHBOIL is a downloader written in C#. Its job is to retrieve and install further malicious payloads and keep them in place. Over time the group added stronger code obfuscation, using a commercial tool called Eziriz .NET Reactor by late 2025, and introduced checks to detect whether the malware was running in a sandbox. Earlier versions ran once, while a late-2025 version ran on a two-minute timer so it could fetch newer payloads from its command-and-control server. Persistence methods also changed, moving between Windows Registry Run keys and scheduled tasks. Late-2025 samples even showed a daily-planner-style interface when run manually, though ESET noted inconsistencies that weakened the disguise.
ESET observed victims in Ukraine across transportation, manufacturing and energy, with activity seen as recently as June 2026. CERT-UA first documented MATCHBOIL in August 2025, but ESET found earlier samples suggesting development began as early as April 2024.