Russian-Aligned Spies Upgrade MATCHBOIL Malware Targeting Ukraine


The Russian-aligned cyber espionage group UAC-0099 has continued developing the MATCHBOIL malware for use in attacks against Ukrainian companies involved in transportation, manufacturing, and energy. Several changes have been made to the malware since 2024, according to research conducted by cybersecurity firm ESET, with newer versions adding techniques designed to make detection and analysis of the malware more difficult.
Researchers at ESET analyzed MATCHBOIL samples collected between April 2024 and April 2026 in a report published on October 8, 2026. Based upon the findings, the downloader appears to be becoming more sophisticated with each new version. While the Ukrainian Computer Emergency Response Team (CERT-UA) first documented the malware in August 2025, earlier samples indicate that the malware had been developing for at least a year prior. 
Matchboy is a C#-based downloader designed for retrieving additional malicious payloads from a command-and-control (C2) server, installing them on compromised systems, and maintaining their presence ESET's telemetry identified victims exclusively in Ukraine, including transportation companies between July and August 2025, a manufacturing organization in December 2025 and a company in the energy sector in June 2026. 
In order to spread the malware, spear-phishing emails containing malicious links are used. Once a recipient clicks the link, an archive containing VBScript is downloaded. MATCHBOIL is then downloaded and executed on the victim's computer, thereby giving the attackers the opportunity to introduce further malicious components. 
Although the level of confidence in UAC-0099's alignment with Russian interests was described as medium, ESET concluded that it was likely aligned with Russian interests.

This group has previously targeted Ukrainian government agencies, financial institutions, and media institutions, proving MATCHBOIL to be another component of its broader cyber espionage activities. 
MATCHBOIL has modified its code so that it is harder to inspect, thereby making its activity less visible.

It was previously obfuscated with basic Unicode, but newer samples use Eziriz .NET Reactor, which complicates reverse engineering. The malware has also been updated to detect virtual or analysis environments and to stop it from running under these conditions. 
Additionally, the malware's execution pattern has changed.

A version seen from late 2025 started checking in roughly once every two minutes for additional or updated components, as opposed to earlier versions that contacted the command-and-control server once to retrieve a payload. It has also evolved over time to keep the malware active on compromised systems, switching between Windows Registry Run keys and scheduled tasks. 
Researchers have also noted attempts to make the malware appear legitimate in the past.

The late-2025 variant was able to display a daily planner interface when manually launched, but interface errors rendered it unconvincing. 
However, the sample identified in February 2026 was more conspicuous, showing a text-search utility. Other malicious tools have also been associated with MATCHBOIL, including MATCHWOK, a backdoor that enables the execution of remote commands, and DRAGSTARE, a cookie and browser credential stealer.
This combination allows the group to expand beyond initial access and engage in further activities on compromised systems. ESET's findings indicate that UAC-0099 continues to refine MATCHBOIL for future operations. There is no accurate figure of the number of organizations affected by the campaign, as neither ESET nor Ukraine's CERT-UA have provided a confirmation of the number of victims.

This article has been indexed from CySecurity News – Latest Information Security and Hacking Incidents

Read the original article: