ESET details MATCHBOIL: UAC-0099 malware installs spying backdoor on Windows
ESET traced nearly two years of changes to MATCHBOIL, a downloader used by the Russia-aligned group UAC-0099 to plant the MATCHWOK espionage backdoor on Windows machines in Ukraine. Victims include transportation firms, a manufacturer and an energy company, with delivery starting from a spear-phishing email and a VBScript file.
- All victims in ESET telemetry were in Ukraine: transport in July–August 2025, a manufacturer in December 2025, energy in June 2026
- MATCHBOIL downloads MATCHWOK, a C# backdoor that can take screenshots and run PowerShell commands
- Since late 2025 it runs on a two-minute timer and uses the Eziriz .NET Reactor obfuscator
- Sandbox checks require at least three uptime events of 7,200 seconds and an OS installed at least ten days earlier
Read next
Security