UAC-0099 has deployed an increasingly evasive downloader called MatchBoil against Ukrainian organizations in the transportation, manufacturing, and energy sectors, according to ESET’s findings.
The operation starts with targeted phishing rather than exploitation of a software vulnerability. Recipients receive a link to an archive containing a VBScript payload, which must be downloaded and manually executed. If that step succeeds, MatchBoil can install on the system and contact command-and-control infrastructure for additional malware.
One documented follow-on payload is MatchWok, a C# backdoor designed to maintain access to compromised computers. ESET’s examination of samples collected from April 2024 to April 2026 shows that MatchBoil has gained stronger obfuscation, sandbox checks, revised persistence mechanisms, and recurring C2 communications.
The infection chain depends on manual VBScript execution
The observed attack begins with a spear-phishing email directing the recipient to an archive. Inside is a VBScript payload that the user must launch manually before MatchBoil can reach the machine.
That requirement creates a visible point of intervention for defenders. Email controls can inspect archive delivery and linked downloads, while endpoint monitoring can flag unexpected script execution originating from user-controlled locations.
Once active, MatchBoil checks whether a particular directory exists on the victim’s system. It terminates if the directory is present. The reporting does not identify the directory, so defenders cannot convert that check into a specific file-system indicator from the available information.
The downloader also collects selected machine details. Those details are subsequently used to identify the victim during C2 communication, although the individual data fields have not been specified.
MatchBoil then retrieves additional payloads from its server. This separates initial delivery from the capabilities ultimately installed: the downloader establishes the route, while the next-stage malware determines what access the operator receives.
Newer samples are harder to inspect
ESET says MatchBoil has been under active development since at least 2024. Samples collected between April 2024 and April 2026 reveal changes in both code organization and resistance to analysis.
Versions from 2024 used relatively simple obfuscation based on Unicode. The 2026 edition instead employs Eziriz .NET Reactor, a commercial protection and obfuscation product for .NET applications. In this context, it makes static inspection and reverse engineering more difficult, but does not itself identify malicious activity.
The newer malware also incorporates sandbox checks. These can help a sample recognize analysis conditions and alter or stop its execution before researchers observe its full behavior. ESET additionally found a less conspicuous interface intended to reduce attention from users and analysts.
Samples compiled or observed before November 2025 were more straightforward to examine than later variants, according to ESET. That distinction matters operationally: detections based narrowly on older code structures may not perform reliably against the protected 2026 edition.
Behavioral evidence therefore becomes more valuable. Script ancestry, persistence changes, repeated outbound requests, and installation of subsequent payloads may remain observable even when static signatures are weakened by obfuscation.
Persistence shifted between Run keys and scheduled tasks
MatchBoil’s developers have revised how the malware survives login and system use.
Early versions combined a registry value with a scheduled task. Later versions abandoned that combination and relied exclusively on the Windows Run key, causing the malware to launch when the affected user logged in.
The authors subsequently returned to scheduled tasks. The source describes that change as occurring “last year” but does not provide a specific calendar date, so the transition cannot be placed more precisely from the cited material.
These variations mean that investigators should not treat one persistence mechanism as definitive for the entire malware family. A Run-key entry may fit one generation, while a scheduled task may correspond to an earlier or later build.
The downloader’s network behavior also changed. By late 2025, MatchBoil had moved beyond a single-run model in which it contacted its server once and installed a next-stage payload. It began running every two minutes, enabling repeated requests for new or updated malware.
That interval is a useful hunting lead, not a universal signature. Analysts should correlate recurring connections with process execution, script activity, persistence artifacts, and payload creation rather than alerting on timing alone.
MatchWok provides the continued-access capability
MatchWok is distinct from MatchBoil. The former is a C# backdoor, while the latter is the downloader used to place or update additional payloads.
In the chain described by ESET, MatchWok gives the attacker persistent access after MatchBoil completes the delivery stage. Repeated polling may also allow the operator to replace or supplement payloads without restarting the entire phishing sequence.
The affected sectors make that access consequential. ESET says UAC-0099 initially concentrated on Ukrainian transportation companies, expanded into manufacturing, and more recently added energy organizations.
The available reporting supports concern about espionage and continued unauthorized access. It does not report confirmed data theft, ransomware deployment, or destructive activity in the MatchBoil campaign. Those outcomes should not be inferred solely from the presence of a backdoor or from the history of other actors discussed alongside UAC-0099.
No formal severity rating or CVSS score applies in the cited account. MatchBoil is malware delivered through phishing, not a disclosed product vulnerability with a set of affected software versions.
UAC-0099 and Sandworm remain separate attribution questions
ESET identifies UAC-0099 as the operator using MatchBoil and describes the group as active since 2023. It assesses with moderate confidence that UAC-0099 is connected to Russian interests, based primarily on its targeting of Ukrainian organizations.
ESET also assesses that UAC-0099 is likely an initial access broker for Sandworm, according to reporting on the researchers’ findings. Sandworm is described as linked to Russia’s military intelligence agency and associated with destructive attacks against Ukraine’s power grid and other infrastructure.
That assessment does not establish that Sandworm operated the MatchBoil activity. The evidentiary boundaries remain important:
- UAC-0099 is the operator identified in the reported campaign.
- MatchBoil is the downloader used in the infection chain.
- MatchWok is a C# backdoor delivered as a follow-on payload.
- The proposed relationship with Sandworm is ESET’s assessment, not proof that Sandworm controlled these incidents.
Keeping those categories separate avoids transferring Sandworm’s historical actions to a campaign where destructive effects have not been reported.
Defenders can hunt the chain even without named indicators
The reporting does not provide hashes, domains, IP addresses, filenames, the directory checked by MatchBoil, or the exact machine attributes sent to the C2 server. It also contains no vendor patch or product-specific remediation because the entry point described is phishing and manual script execution.
Defenders can still investigate the reported behaviors:
- Review spear-phishing messages that link to archives containing VBScript.
- Detect script launches initiated from downloaded archives or user-writable directories.
- Correlate VBScript execution with downloader behavior and the creation or launch of subsequent .NET payloads.
- Inspect Windows Run-key entries, scheduled tasks, and other registry changes around the time of suspicious script execution.
- Hunt for processes making recurring outbound requests, including approximately two-minute patterns, while treating the cadence as supporting evidence rather than a standalone indicator.
- Examine processes that gather host details before initiating repeated C2 communication.
- Use runtime and behavioral analysis where static inspection is obstructed by Eziriz .NET Reactor or sandbox-aware execution.
The most useful detection opportunity remains the full sequence: targeted archive delivery, manual VBScript execution, persistence creation, host identification, recurring C2 contact, and installation of a second-stage backdoor. Individually, several of those actions can be legitimate. Together, in the observed order and context, they provide a stronger basis for investigation.




