Skip to main content
See who owns your news
Published • loading... • Updated

What Is MATCHBOIL? The Russia-Aligned Malware that Installs a Spying Backdoor

ESET researchers traced almost two years of changes to MATCHBOIL, a downloader that the Russia-aligned group UAC-0099 uses to plant a second program on Windows machines in Ukraine. GUI displayed at MATCHBOIL’s runtime (Source: ESET) Every victim in ESET’s telemetry was in Ukraine: transportation companies in July and August 2025, a manufacturer in December 2025, and an energy company in June 2026. The program MATCHBOIL installs is a spying tool,…
DisclaimerThis story is only covered by news sources that have yet to be evaluated by the independent media monitoring agencies we use to assess the quality and reliability of news outlets on our platform. Learn more here.

7 Articles

ESET reconstructs two years of evolution of MATCHBOIL, the downloader of UAC-0099 - group aligned with Russian interests and possible initial access broker for Sandworm - used against transport, manufacturing and energy in Ukraine. From the artisan offset to .NET Reactor, to the latest anti-sandbox controls. The article Let's see how the UAC-0099 group has transformed a cat agenda into a backdoor against Ukrainian infrastructure comes from (in) …

Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • There is no tracked Bias information for the sources covering this story.

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

Help Net Security broke the news on Thursday, October 8, 2026.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal