What Is MATCHBOIL? The Russia-Aligned Malware that Installs a Spying Backdoor
7 Articles
7 Articles
ESET reconstructs two years of evolution of MATCHBOIL, the downloader of UAC-0099 - group aligned with Russian interests and possible initial access broker for Sandworm - used against transport, manufacturing and energy in Ukraine. From the artisan offset to .NET Reactor, to the latest anti-sandbox controls. The article Let's see how the UAC-0099 group has transformed a cat agenda into a backdoor against Ukrainian infrastructure comes from (in) …
ESET traces MATCHBOIL malware changes targeting Ukrainian industry
ESET researchers have traced MATCHBOIL malware changes affecting Ukrainian industries. The downloader appeared at transport, manufacturing and energy organisations, while later variants changed how they communicated, persisted and resisted analysis. The findings do not establish attacks on industrial controllers.
MATCHBOIL Malware Uses Cloudflare-Hidden C2 Servers to Deliver Backdoor Payloads
MATCHBOIL, a C# malware downloader linked to UAC-0099, uses command-and-control (C2) servers hidden behind Cloudflare to deliver backdoor payloads. Its changing code shows how the group has moved from a simple downloader toward repeated server contact, stronger code hiding, and checks designed to stop security researchers from studying infections. The observed victims were all in […]
ESET details evolving MATCHBOIL malware used by Russia-aligned UAC-0099 in attacks on Ukrainian sectors
ESET Research says the custom C# downloader has grown more sophisticated since 2024 and has been observed in transport, manufacturing and energy organizations in Ukraine IN BRIEFKEY TAKEAWAYSFAQs ESET Research has documented the evolution of MATCHBOIL, a custom C# downloader … Read the full press release →
What is MATCHBOIL? The Russia-aligned malware that installs a spying backdoor
ESET researchers traced almost two years of changes to MATCHBOIL, a downloader that the Russia-aligned group UAC-0099 uses to plant a second program on Windows machines in Ukraine. GUI displayed at MATCHBOIL’s runtime (Source: ESET) Every victim in ESET’s telemetry was in Ukraine: transportation companies in July and August 2025, a manufacturer in December 2025, and an energy company in June 2026. The program MATCHBOIL installs is a spying tool,…
Coverage Details
Bias Distribution
- There is no tracked Bias information for the sources covering this story.
Factuality
To view factuality data please Upgrade to Premium







