Breaking
Cyber CrimeDeveloping Story

UAC-0099 Turns MATCHBOIL Into Long-Term Tool

ESET tracked MATCHBOIL versions from April 2024 to April 2026, linking the downloader to Russia-aligned UAC-0099 operating in Ukraine.

··3 hours ago·7 min read
laptop compute displaying command prompt
Photo by X on Unsplash

A Russia-aligned espionage crew didn't treat its downloader as a one-off piece of code — it kept rewriting it for two years, layering in stronger obfuscation, sandbox detection, and a shifting execution model while the operators kept using it in the field. That is the picture ESET painted on October 8, when it published research tracing the evolution of a C# downloader called MATCHBOIL.

ESET attributed the tool to UAC-0099, a group it has assessed with medium confidence to be aligned with Russian interests. The group's targets, per ESET, have included Ukrainian government organizations, financial institutions, and media. MATCHBOIL victims in Ukraine span transportation, manufacturing, and energy, with activity observed as recently as June 2026.

The downloader itself isn't new to the record: Ukraine's Computer Emergency Response Team (CERT-UA) first documented MATCHBOIL in August 2025. But ESET's review of older samples suggests the code was already being developed as early as April 2024. That matters less as a historical footnote and more as a signal about how the operators work — they appear to have iterated on a single implant rather than discarding it.

What MATCHBOIL Actually Does

At its core, MATCHBOIL is a C# downloader. Its job is to retrieve, install, and establish persistence for additional payloads — the classic first-stage function that lets an attacker stage follow-on tools without shipping everything in a single binary. Because the downloader is written in C#, it fits naturally into the .NET ecosystem, which is also why the operators' later choices around obfuscation tools matter.

ESET evaluated MATCHBOIL versions that were either compiled or observed between April 2024 and April 2026. Its finding: each successive version was more sophisticated than the one preceding it. The research was published on October 8.

The broader context is a Russian state hacking effort aimed at Ukraine that has drawn repeated attention from security researchers. ESET's write-up sits alongside other documented campaigns in the same theater — including a report on how another Russian state hacking group exploited a Microsoft Office flaw in Ukraine and EU cyber-attacks, detailed separately.

From Unicode Tricks to a Commercial Obfuscator

Earlier MATCHBOIL samples leaned on a fairly basic defensive layer: unprintable Unicode characters and string encryption to make the code harder to inspect casually. That approach gave way by late 2025, when UAC-0099 switched to the Eziriz .NET Reactor obfuscator — a tool capable of code virtualization and control-flow obfuscation. Moving from hand-rolled tricks to a mature .NET obfuscator changes the analysis economics for defenders: virtualization and control-flow manipulation can make static inspection substantially more expensive.

Alongside the obfuscation shift came sandbox checks. Later samples added logic designed to determine whether MATCHBOIL was running inside a sandboxed environment. ESET said these capabilities were introduced gradually from late 2025. The timing and the pacing suggest a deliberate, incremental hardening of the implant rather than a single feature drop.

For defenders, sandbox detection in a downloader is a signal about intent. It means the operators aren't just trying to avoid signature-based detection; they're trying to blunt automated analysis pipelines that many incident response teams rely on to triage unknown binaries quickly.

The Two-Minute Timer Change

MATCHBOIL's execution model also shifted over the tracked period. Earlier samples behaved as one-shot downloaders — they fetched what they needed and stopped. A version from late 2025 instead ran on a two-minute timer, which allowed it to pull a newer payload from its command-and-control (C2) server. That's a meaningful behavioral change: a timed poll gives the operators a way to deliver fresh payloads to an already-compromised host without needing to re-infect it.

The change also implies the C2 infrastructure was expected to remain available and responsive across multiple check-ins. A one-shot downloader tolerates a single point of failure; a timed one is built for iteration.

Persistence Keeps Shifting

The persistence mechanism MATCHBOIL set up for its payloads moved in step with the rest of the implant. The 2024 samples combined a Windows Registry Run key value with a scheduled task — two independent autostart mechanisms layered together. A July 2025 version relied on Run key entries alone. Later samples moved back to scheduled tasks.

That back-and-forth across Run keys and scheduled tasks is worth noting because each approach has different detection and forensic characteristics. Run keys are a common, well-understood persistence location that defenders routinely monitor; scheduled tasks offer more scheduling flexibility and can be tuned to blend into legitimate system activity. The operators' oscillation between the two suggests they were testing what worked in their target environments.

ESET's account of the downloader's evolution adds up to a picture of UAC-0099 treating MATCHBOIL as a component under active development, not a static artifact dropped once and forgotten.

Fake Interfaces, Weaker Disguises

Late-2025 samples introduced a daily-planner-style graphical interface, displayed when MATCHBOIL was executed manually. The idea appears to be plausible deniability for anyone who double-clicks the binary — a user sees a calendar or planner rather than an obviously malicious program. But ESET noted several inconsistencies that weakened the disguise.

By February 2026, a sample instead displayed a less conspicuous utility for searching text files with regular expressions. That's a narrower, more technical-looking facade than a planner — the kind of utility that might not raise alarms in a developer or IT workstation context, and that is far less likely to be scrutinized by a casual user than a half-finished calendar app.

The shift from planner to regex search utility suggests the operators had moved beyond the planner concept. It also hints at what kinds of hosts they were comfortable being seen on.

What ESET Told Defenders

ESET's assessment of the timeline points to sustained investment in the downloader. The firm framed the activity as evidence that UAC-0099 has treated MATCHBOIL as an evolving component of its toolkit rather than a static downloader.

"This demonstrates a keen interest by UAC-0099 operators in improving their downloader, not only to avoid detection by security solutions, but also to use it as a key part of their toolset in future attacks," ESET concluded.

— ESET, in research published October 8

That conclusion is worth taking at face value with one caveat: it is ESET's inference from telemetry and sample analysis, not a statement of confirmed future plans. The wording is careful — improving the downloader for future attacks, not a specific forecast of what those attacks will be.

The Numbers Behind Two Years of Iteration

The clearest way to read ESET's findings is through the concrete data points it published. Each one maps to a version or observation window.

  • MATCHBOIL versions compiled or observed between April 2024 and April 2026
  • Earlier samples suggest development may have begun as early as April 2024
  • First documented by Ukraine's CERT-UA in August 2025
  • Obfuscation, sandbox checks, and execution changes added from late 2025
  • A July 2025 version relied on Run key entries for persistence
  • A February 2026 sample displayed a regex text-search utility
  • Activity observed as recently as June 2026
  • A late 2025 version ran on a two-minute timer to fetch newer payloads

Read together, these dates trace a cadence: development activity predating the public CERT-UA documentation, a cluster of capability additions in late 2025, and continued field activity into mid-2026.

Tracking a Moving Implant

For defenders, the MATCHBOIL timeline reinforces a familiar but uncomfortable reality: first-stage downloaders are rarely fire-and-forget. When operators have a working foothold, they have an incentive to keep the staging tool current, and each revision resets some of the assumptions baked into older detections.

The specific technical shifts ESET documented are worth tracking in detection engineering. A move to Eziriz .NET Reactor means static signatures and simple .NET decompilation analysis may degrade. Sandbox checks mean automated dynamic analysis may produce false negatives if the sandbox is fingerprinted. A two-minute timer means network monitoring for C2 beacons needs to account for repeated, periodic callbacks rather than a single fetch. And rotating persistence between Run keys and scheduled tasks means endpoint monitoring should cover both, not just the more commonly abused one.

The geographic and sectoral scope — Ukrainian government, financial, and media targets, plus transportation, manufacturing, and energy victims — also narrows where defenders should prioritize hunting. Organizations in those sectors, particularly those with Ukrainian operations or supply-chain links, are the natural place to look for the indicators ESET published.

Why This Matters Beyond Ukraine

The immediate stakes are concentrated in Ukraine, where ESET says MATCHBOIL victims have been observed across transportation, manufacturing, and energy, and where the broader Russian state hacking campaign continues. But the way ESET describes MATCHBOIL's development has wider implications for anyone defending against a persistent adversary.

A downloader that survives two years of iteration is a downloader that has been tested against real defenses. If ESET's assessment is right that UAC-0099 views MATCHBOIL as a key part of its toolset for future attacks, then the capabilities added over that period — obfuscation, sandbox checks, timer-based execution, rotating persistence — are the capabilities defenders will encounter next. That doesn't mean every organization is a target; it means the detection logic built around MATCHBOIL's earlier versions may already be stale.

The practical takeaway is narrower than a call to arms: treat published indicators as a starting point, and expect the implant to keep changing. ESET's research is a snapshot of one tool in one campaign, and the pattern it documents — gradual, deliberate improvement of a staging component — is the part most likely to repeat. Organizations that can't afford to re-tune detections every few months should at minimum track when the next version appears.

#uac-0099#matchboil#eset#ukraine#russia#malware

Sources

Iliyas

Founder & Editor, Xploitwire

This article was written and reviewed against the sources listed above before publication, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories