MATCHBOIL Malware Deploys Russian-Linked Spyware in Ukraine
Russia-aligned threat group UAC-0099 is using the MATCHBOIL malware to install a spying backdoor on Windows systems, exclusively targeting organizations in Ukraine.

ESET researchers have detailed MATCHBOIL, a sophisticated downloader malware employed by the Russia-aligned threat group UAC-0099. This malware has been observed deploying a secondary spying tool onto Windows systems, primarily targeting victims within Ukraine.
The campaign, tracked by ESET, spans nearly two years of activity, with victims exclusively identified within Ukraine. The targeted sectors include transportation companies, a manufacturing firm, and an energy company, with incidents reported between July 2025 and June 2026. The primary function of MATCHBOIL is to establish an initial foothold and then install a more persistent spying tool, facilitating espionage operations.
MATCHBOIL itself acts as a downloader, a common technique used by threat actors to maintain flexibility and evade detection. By first deploying a downloader, attackers can dynamically choose and install the final payload, adapting to the target environment or changing operational needs. This modular approach allows for a stealthier initial compromise before the more intrusive spying capabilities are activated.
The spying tool deployed by MATCHBOIL is designed to facilitate espionage, though specific details regarding its exact capabilities, such as data exfiltration methods or surveillance functions, are not fully elaborated in the initial reporting. However, the consistent targeting of critical infrastructure and industrial sectors in Ukraine suggests a focus on intelligence gathering relevant to the ongoing geopolitical landscape.
The threat actor behind MATCHBOIL, UAC-0099, is identified as being aligned with Russia. This attribution aligns with a broader pattern of cyber operations targeting Ukraine, often involving state-sponsored or state-aligned groups. The prolonged nature of the campaign, spanning almost two years, indicates a sustained effort and a degree of success in evading detection and disruption.
ESET's telemetry provided the basis for identifying the victims and the timeline of the attacks. The researchers observed the malware's runtime graphical user interface (GUI), which offers a glimpse into the malware's operational characteristics. The consistent pattern of deployment and the nature of the payload underscore the malicious intent behind MATCHBOIL.
The implications of this campaign are significant for Ukrainian organizations, particularly those in critical sectors. The deployment of a spying backdoor poses a direct threat to sensitive data, operational integrity, and national security. The use of a downloader like MATCHBOIL highlights the evolving tactics, techniques, and procedures (TTPs) employed by sophisticated threat actors.
While specific technical details on the exploitation vector for MATCHBOIL are not yet public, the campaign's focus on espionage and its exclusive targeting of Ukraine by a Russia-aligned group underscore the persistent cyber threats faced by the nation. Further analysis by security researchers is expected to reveal more about the malware's intricacies and the broader objectives of UAC-0099.
The latest analysis reveals that the Matchboil downloader, attributed to the Sandworm-linked UAC-0099 group, has undergone significant evolution since at least April 2024. Recent iterations, observed in 2026, feature a less conspicuous graphical user interface and have transitioned to a DLL file executed by a custom C# loader, enhancing its evasion capabilities. Furthermore, the malware now terminates if the operating system was installed more than ten days prior to execution, indicating a more sophisticated defense-evasion strategy.