ESET researchers have documented nearly two years of changes to MATCHBOIL, a downloader used by the Russia-aligned group UAC-0099 to install a spying backdoor on Windows machines. All victims in ESET's telemetry were in Ukraine: two transportation companies in mid-2025, a manufacturer in December 2025, and an energy company in June 2026. The infection chain begins with a spear-phishing link that leads to an archive containing a VBScript, which downloads and runs MATCHBOIL. The malware fingerprints the machine using its CPU ID and BIOS serial number, makes HTTPS requests to the group's server, and pulls the payload from the second response, where it is hidden as hex-encoded text.
The payload is MATCHWOK, a C# backdoor capable of taking desktop screenshots and executing PowerShell commands. MATCHBOIL writes it to a folder under %LOCALAPPDATA% and sets up persistence through a scheduled task or registry key. The tool has evolved: the payload folder moved from DeviceMonitor in 2024 to MeowCheck in late 2025 and SMTPClient by April 2026. Early versions ran once; by late 2025, MATCHBOIL retried every two minutes, used the commercial obfuscator Eziriz .NET Reactor, and added sandbox checks based on Windows event logs and OS installation age.
ESET attributes UAC-0099 to Russian interests with medium confidence, based on targeting. The group has previously hit government bodies, financial institutions, and media in Ukraine, so the transport, manufacturing, and energy victims represent an expansion. Researcher Fernando Tavella said UAC-0099 has acted as an initial access broker for Sandworm, another Russia-aligned APT group, and may be seeking victims that could interest other groups. Ukraine's CERT-UA documented MATCHBOIL in August 2025, and compilation timestamps point to mid-2024, meaning the tool likely ran for about a year before being publicly described.