MATCHBOIL Downloader Evolves with New Obfuscation and Evasion Tactics
ESET Research details the ongoing evolution of the MATCHBOIL malware, used by the Russia-aligned UAC-0099 APT group, highlighting new obfuscation techniques and sandbox evasion methods observed between 2024 and 2026.

ESET researchers have meticulously tracked the evolution of MATCHBOIL, a custom C# downloader employed by the Russia-aligned UAC-0099 advanced persistent threat (APT) group. This malware serves as a critical component in the group's arsenal, responsible for downloading, installing, and establishing persistence for further malicious payloads on victim systems. While CERT-UA first documented MATCHBOIL in August 2025, ESET's analysis reveals that its development predates this, with the earliest analyzed versions dating back to April 2024 and the most recent from April 2026. This chronological examination showcases a consistent pattern of improvement, indicating MATCHBOIL's significance to UAC-0099's operational capabilities.
ESET's investigation began in February 2026 after discovering two MATCHBOIL samples on VirusTotal that communicated with a domain previously linked to UAC-0099. This discovery prompted a deeper dive into ESET's telemetry, uncovering earlier samples from November and December 2025 exhibiting similar malicious behaviors. Further analysis unearthed even older samples, compiled in April 2024 and observed in ESET telemetry throughout July and August 2025. The compilation timestamps of the first publicly known samples documented by CERT-UA in August 2025 also suggest that UAC-0099 was actively developing MATCHBOIL around mid-2024.
The evolution of MATCHBOIL is marked by significant technical advancements. Early versions relied on simpler methods like Unicode symbol renaming for code obfuscation. However, more recent iterations have adopted sophisticated commercial obfuscators, notably Eziriz .NET Reactor, making static analysis considerably more challenging. This shift reflects a growing emphasis on operational security and evasion by the UAC-0099 group.
Furthermore, MATCHBOIL has incorporated increasingly robust techniques to detect and thwart sandboxed environments. These anti-analysis measures are designed to prevent security researchers and automated tools from effectively studying the malware's behavior. The continuous refinement of these evasion tactics underscores the threat actor's determination to maintain the stealth and efficacy of their operations.
Victimology data gathered from ESET telemetry indicates a consistent targeting of entities within Ukraine. Between July and August 2025, transportation companies were observed as targets. In December of the same year, a manufacturing firm fell victim. More recently, in June 2026, samples were detected at a company operating in the energy sector. The two samples found on VirusTotal in February 2026 were also uploaded from Ukraine, reinforcing the geographical focus of UAC-0099's campaigns.
UAC-0099 is characterized as a cyberespionage group with a primary focus on Ukrainian governmental organizations, financial institutions, and media outlets. With medium confidence, researchers attribute the group's activities to Russian interests. UAC-0099 also acts as an initial access broker for the notorious Sandworm group, known for its destructive cyberattacks, particularly within Ukraine. The group has been active since at least 2022, with its initial reporting by CERT-UA occurring in June 2023. Beyond MATCHBOIL, UAC-0099 is known to deploy LONEPAGE, another PowerShell downloader.
The MATCHBOIL malware is typically distributed via spearphishing emails containing malicious links. Upon clicking, users are prompted to download an archive file containing a VBScript payload. This script, when manually executed by the victim, initiates the download and execution of MATCHBOIL. At runtime, MATCHBOIL performs several checks, including verifying the existence of a specific directory in %LOCALAPPDATA% used for payload installation. It also gathers system information such as the CPUID and BIOS serial number to identify the victim during C&C communication.
Subsequent communication with the C&C server involves three distinct HTTPS requests. The first retrieves a numeric value used in a subsequent header, potentially indicating which payload to download. The second request receives a hex-encoded payload embedded within HTML-formatted code, extracted using sample-dependent regular expressions. The third request fetches a configuration string saved to a file. In most observed cases, the downloaded payload is MATCHWOK, a C# backdoor exclusively used by UAC-0099.