
Russia-Aligned Spies Retool MATCHBOIL Malware and Widen Attacks to Ukrainian Transport, Manufacturing and Energy Firms
ESET says UAC-0099, a group it describes as able to act as an initial access broker for Sandworm, planted its rebuilt MATCHBOIL downloader at Ukrainian transportation, manufacturing and energy companies, adding fake planner screens, sandbox checks and a new DLL variant while leaving a trail of file paths, scheduled tasks and HTTP headers defenders can hunt.
Priya Shah, Threat IntelSingapore6 min read
SINGAPORE - A Russia-aligned espionage group that has long gone after Ukrainian government agencies has been planting a steadily rebuilt piece of malware inside Ukrainian transportation, manufacturing and energy companies, according to research published on Thursday by the Slovak security company ESET. Every victim of the downloader, which ESET and Ukraine's government computer emergency response team, CERT-UA, call MATCHBOIL, that ESET found in its own telemetry was in Ukraine: multiple transportation companies in July and August 2025, a manufacturing company in December 2025 and a company in the energy sector in June 2026. ESET describes the group, tracked as UAC-0099, as a cyberespionage operation targeting government organizations, financial institutions and media in Ukraine, and says it "can act as an initial access broker for Sandworm," the Russia-aligned group known for destructive attacks on Ukraine.
The infection begins with an ordinary lure. According to ESET's analyst Fernando Tavella, the group sends spearphishing emails with a malicious link that downloads an archive holding a VBScript file; the victim has to be talked into running the script by hand, and the script then downloads and runs MATCHBOIL. The downloader, written in C#, fingerprints the machine through Windows Management Instrumentation queries, collecting the CPUID and BIOS serial number and, in later versions, the username, the network card's MAC address and the computer's model and manufacturer. It then makes three HTTPS requests to its command server: one returns a number, one returns HTML with a hex-encoded payload that MATCHBOIL pulls out with a regular expression such as <script>(.*?)</script>, and one returns a string saved as a configuration file. In most cases, ESET said, the payload is MATCHWOK, a C# backdoor used only by UAC-0099. "For example, it can take screenshots of the victim desktop or execute PowerShell commands on the victim's computer," Mr. Tavella told Help Net Security.

ESET said it began looking at MATCHBOIL in February 2026, when two samples uploaded to VirusTotal were seen talking to a domain previously attributed to UAC-0099. That led it to more samples in its own telemetry, some compiled in April 2024. CERT-UA first documented MATCHBOIL in August 2025, but ESET said compilation timestamps suggest the group was already developing it in 2024. Over roughly two years, ESET said, the operators turned a one-shot downloader into one that checks in with its server every two minutes, swapped custom string encryption and unprintable Unicode names for the Eziriz .NET Reactor obfuscator, and switched persistence from a registry value plus a scheduled task, to a Run key alone, and then to a scheduled task.
The newer builds also try to fool both people and sandboxes. Samples from late 2025 show a fake daily planner if someone opens the file directly; ESET noted that the window's title is misspelled "Dairy," which it said suggests planning one's milk product intake, and that both text boxes are labeled "Today." The malicious code runs only when the file is launched with the argument -auto, after which it creates the mutex Global\PlannerAssistant. Before calling home, it reads Windows System event 6013, which records uptime, using one regular expression in English and one in Russian, and proceeds only if at least three events show uptime of 7,200 seconds or more. It also checks whether a debugger is attached. A February 2026 sample added the argument -plans; another that month used -renew and swapped the planner for a fake regular expression search tool. An April 2026 variant, which CERT-UA calls MATCHBOIL.V2, is the first delivered as a DLL run by a custom C# loader, and it adds a check on how long ago the operating system was installed, with a 10-day threshold.

For defenders, ESET's write-up is mostly a list of places to look, and the names change with each version. The 2024 builds installed their payload under %LOCALAPPDATA%\DeviceMonitor with a config.ini file, set a Run value named DeviceMonitor under HKCU\Software\Microsoft\Windows\CurrentVersion\Run and created a scheduled task named Updates\CheckTask. The late 2025 builds dropped the payload at %LOCALAPPDATA%\MeowCheck\MeowMeowProgramm.exe, wrote a temporary file named WallpappersSet.jpg to the user's Pictures folder, saved configuration as config.library-ms under C:\Users\Public\Libraries and created a task named UpdateCheckers\DailyPlanner that runs every seven minutes. The April 2026 variant installs %LOCALAPPDATA%\SMTPClient\SMTPClientApplication.exe and persists through a task named Checker under a MailClient folder. ESET also listed the payload file name Thumbs.db as a masquerading technique.
On the network side, the builds ESET described send a custom HTTP header named SN carrying the victim fingerprint and a 25-character User-Agent string; the numeric value from the first request travels in a header named Count in 2024 builds and Answer in late 2025 builds. ESET said the group hosts command servers on virtual private servers such as BitLaunch, hides them behind Cloudflare and uses Let's Encrypt certificates that are not reused across domains. Its published indicators include the domains virtualdailyplanner[.]pro and telemetry-conf[.]com, flycloud-service[.]com at 64.95.10[.]223 and airarticlegenerate[.]com at 64.95.13[.]210, along with SHA-1 hashes such as 050926727CDD74F0B3A8A098E60B76D10FB06B14 for the April 2026 sample. The full list is in ESET's malware-ioc repository on GitHub.

ESET's report lands three days after researchers at TrendAI published their own history of an overlapping intrusion set, which it says has run spearphishing campaigns since at least 2022 against Ukrainian government, defense, border guard and logistics targets using more than 10 malware families. TrendAI described a previously undocumented .NET information stealer and remote access tool it calls ASHVEIN, and a July 2026 chain documented by CERT-UA in which a malicious Notepad++ plugin, LUNCHPOKE, deploys a .NET loader called BURNYBEAR and MATCHBOIL.V2. TrendAI said most confirmed command domains used the registrar Regery.com and Cloudflare, with backend servers clustered in AS399629, BL Networks, the same provider ESET lists for two of its IP addresses. TrendAI's advice includes watching for executables created under C:\Users\Public\Libraries, renamed copies of schtasks.exe and Notepad++ loading DLLs from unusual plugin locations, and it said its own telemetry showed activity against transport and logistics operators.
ESET's attribution is hedged. It said it believes with medium confidence, based on targeting, that UAC-0099 is aligned with Russian interests, and it describes the Sandworm link as a role the group can play rather than tying any of the new victims to a destructive attack. Mr. Tavella said the widening list of victims could be deliberate. "UAC-0099 has been targeting different entities in Ukraine. We believe that the group has different interests and their expansion in the victimology could mean that they are seeking to maximise their impact in UA," he told Help Net Security. "Let's remember that this group has been an initial access broker of Sandworm, another Russia-aligned APT group, so it is possible they are seeking victims that can be of interest for other APT groups that UAC-0099 can assist." ESET, which sells private threat intelligence reports, did not name the victim companies or say whether any data was taken.
Sources:
- ESET Research: MATCHBOIL: New tricks, same old evil intentions (ESET Research, Oct 8, 2026)
- GitHub: ESET malware-ioc repository (GitHub)
- Help Net Security: What is MATCHBOIL? (Help Net Security, Oct 8, 2026)
- TrendAI: Earth Sirrush: A Russia-Aligned Intrusion Set (TrendAI Research, Oct 5, 2026)
- CERT-UA: MATCHBOIL report (CERT-UA, August 2025)
- CERT-UA: UAC-0099 report (CERT-UA, June 2023)
- CERT-UA: MATCHBOIL.V2 report (CERT-UA, July 2026)
Priya Shah covers threat intelligence, intrusion analysis, and adversary tradecraft for SOCtember from Singapore.
Related stories
Threat Intel
FBI Seizes Integrity Tech Hacking Tools as Allies Detail How China-Linked Hackers Steal Government Email
Threat Intel
Rapid7 Tracks BPFDoor and AVERAT Implants Mimicking Asian Mail Gateways
Threat Intel
Iran-Linked Hackers Posing as Dubai Airports Recruiters Hide Malware in a Visual Studio Coding Test
Detection
Microsoft Warns ClickFix Lures Now Hide Their Payload in the Browser Cache
Response
FBI and Secret Service Warn FortiBleed Hackers Are Locking Some Fortinet Customers Out of Their Own Firewalls
Detection