Threat reportAPTTL-2026-3058
UAC-0099 (MATCHBOIL) Downloader Gets Stealthier .NET Reactor Obfuscation, Sandbox Checks and Rotating Persistence in Attacks on Ukraine
UAC-0099 (MATCHBOIL) Downloader Gets Stealthier .NET Reactor (TL-2026-3058), also tracked as MATCHBOIL, is a high-severity advanced persistent threat campaign, first published 2026-10-08 and last reviewed 2026-10-09. It is attributed to UAC-0099 (Russia) with medium confidence, affects Microsoft Windows, maps to 29 MITRE ATT&CK techniques (T1005, T1027, T1036.005), and is covered by 9 detection rules and 42 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 29MITRE ATT&CK
- Actors
- 1UAC-0099
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 42Indicators of compromise
Key facts for TL-2026-3058
- Threat ID
- TL-2026-3058
- Also known as
- MATCHBOIL, MATCHBOIL.V2, MATCHWOK
- Severity
- HIGH
- Status
- ACTIVE
- Category
- APT
- First published
- Last reviewed
- Attribution
- UAC-0099
- Attribution confidence
- MEDIUM
- Nation-state nexus
- Russia
- Motivation
- ESPIONAGE
- Target sectors
- transport, manufacturing, energy, government administration, defense, finance, news - media
- Target regions
- ukraine
- Detection rules
- 9
- Indicators of compromise
- 42
- Updates
- 2026-10-09 · 3 updates · revalidated 3× · latest source
Malware and tooling in UAC-0099 (MATCHBOIL) Downloader Gets Stealthier .NET Reactor
Malware and tooling: DRAGSTARE, LONEPAGE, MATCHBOIL, MATCHWOK, Eziriz .NET Reactor
How UAC-0099 (MATCHBOIL) Downloader Gets Stealthier .NET Reactor works
ESET research (published 2026-10-08) details the evolution of MATCHBOIL, a C# downloader used by the Russia-aligned UAC-0099 group to install the MATCHWOK C# backdoor on Ukrainian transportation, manufacturing and energy organizations. Samples compiled between April 2024 and April 2026 show a shift from a one-shot downloader to a repeating dropper with Eziriz .NET Reactor obfuscation, uptime and OS-age sandbox checks, decoy GUIs and changing persistence.
UAC-0099 is a cyber-espionage cluster tracked by CERT-UA since June 2023 and active since at least 2022, historically targeting Ukrainian government, financial and media organizations. ESET assesses with medium confidence that the group is aligned with Russian interests and that it may act as an initial access broker for Sandworm (APT44, GRU Unit 74455); no access hand-offs involving the observed victims were established. The group also uses LONEPAGE, a script downloader that CERT-UA has documented in WinRAR-exploit and LNK/HTA phishing chains.
Initial access is spear-phishing: the email carries a link to an archive containing a VBScript that the victim must run manually. The VBScript downloads and executes MATCHBOIL, a custom C# downloader. MATCHBOIL fingerprints the host (CPU ID, BIOS serial; later versions add username, MAC address of the first network interface, and computer model/manufacturer) and sends it in an SN HTTP header alongside a 25-character User-Agent. It performs three HTTPS requests: the first returns a numeric value reused in the second; the second returns HTML-like content from which a hex-encoded payload is extracted by a sample-specific regex (e.g. <script>(.*?)</script>) and hex-decoded; the third returns a string saved as a configuration file. The payload, usually the MATCHWOK C# backdoor (screenshots, PowerShell command execution), is written to a folder under %LOCALAPPDATA% (MATCHBOIL exits if the folder already exists) and set to relaunch via a scheduled task or Run key. The payload is started through WMI (Win32_Process via ManagementClass).
Evolution (ESET): 2024 samples use unprintable-Unicode class/method names and XOR/shift string encryption, drop to %LOCALAPPDATA%\DeviceMonitor and persist with the HKCU Run value DeviceMonitor plus scheduled task Updates\CheckTask, behaving as a one-shot downloader. July 2025 samples run async Tasks and persist only via the Run key. From November-December 2025 builds use Eziriz .NET Reactor (code virtualization, control-flow obfuscation), show a decoy daily-planner GUI when run without -auto, use mutex Global\PlannerAssistant, drop to %LOCALAPPDATA%\MeowCheck\MeowMeowProgramm.exe, poll the C2 on a two-minute timer and persist as scheduled task UpdateCheckers\DailyPlanner running every seven minutes. Sandbox checks read System event ID 6013 via EventLogReader, parse uptime in English and Russian, require at least three events showing >=7,200 s uptime, and test Debugger.IsAttached. Temporary files include WallpappersSet.jpg (Pictures) and config.library-ms (C:\Users\Public\Libraries). February 2026 builds add -plans and -renew arguments and a regex-search-utility decoy. An April 2026 variant (CERT-UA: MATCHBOIL.V2) is the first DLL form, run by a custom C# loader, adds an OS install-date check with a 10-day threshold, and drops %LOCALAPPDATA%\SMTPClient\SMTPClientApplication.exe persisted by scheduled task Checker under MailClient. A recent VBScript dropper persists a C# loader that runs MATCHBOIL.
ESET-observed victims were all in Ukraine: multiple transportation companies (July-August 2025), a manufacturer (December 2025) and an energy company (June 2026). Infrastructure is rented VPS (BitLaunch / BL Networks) and Cloudflare-fronted domains with non-reused Let's Encrypt certificates. CERT-UA's August 2025 reporting (as relayed by The Record) described court-summons-themed phishing against government, military and defense organizations, with MATCHBOIL deploying MATCHWOK and the DRAGSTARE infostealer. Caveat: Dark Reading returned HTTP 403, so facts derive from ESET's WeLiveSecurity report and secondary coverage; CERT-UA's advisories were not directly retrieved; BeaconBeagle returned 404 for both C2 IPs (no match data).
MITRE ATT&CK techniques used in TL-2026-3058
Collection
T1005 Data from Local System; T1113 Screen Capture
Defense Evasion
T1027 Obfuscated Files or Information
Stealth
T1036.005 Masquerading: Match Legitimate Resource Name or Location; T1140 Deobfuscate/Decode Files or Information; T1218.005 System Binary Proxy Execution: Mshta; T1497.001 Virtualization/Sandbox Evasion: System Checks; T1622 Debugger Evasion; T1678 Delay Execution
Execution
T1047 Windows Management Instrumentation; T1059.001 Command and Scripting Interpreter: PowerShell; T1059.005 Command and Scripting Interpreter: Visual Basic; T1106 Native API; T1204.001 User Execution: Malicious Link; T1204.002 User Execution: Malicious File
Persistence
T1053.005 Scheduled Task/Job: Scheduled Task; T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
Command and Control
T1071.001 Application Layer Protocol: Web Protocols; T1105 Ingress Tool Transfer; T1132.001 Data Encoding: Standard Encoding; T1573.002 Encrypted Channel: Asymmetric Cryptography
Discovery
T1082 System Information Discovery
Credential Access
T1539 Steal Web Session Cookie; T1555.003 Credentials from Password Stores: Credentials from Web Browsers
Initial Access
T1566.002 Phishing: Spearphishing Link
Resource Development
T1583.001 Acquire Infrastructure: Domains; T1583.003 Acquire Infrastructure: Virtual Private Server; T1587.001 Develop Capabilities: Malware; T1588.002 Obtain Capabilities: Tool
Affected products and versions in UAC-0099 (MATCHBOIL) Downloader Gets Stealthier .NET Reactor
- Microsoft — Windows
Vulnerable versions: Windows endpoints in targeted Ukrainian organizations (no specific versions reported)
Remediation for UAC-0099 (MATCHBOIL) Downloader Gets Stealthier .NET Reactor
Immediate actions
- Block and sink the C2 domains and IPs listed in the IOC set; hunt proxy/DNS logs for historical contact
- Hunt for %LOCALAPPDATA%\DeviceMonitor, \MeowCheck, \SMTPClient and scheduled tasks Updates\CheckTask, UpdateCheckers\DailyPlanner, MailClient\Checker
- Quarantine mail links resolving to archives that contain .vbs files
Workarounds
- Disable Windows Script Host for users who do not need it
- Train staff in Ukrainian critical-infrastructure sectors on archive-with-script phishing lures
Longer-term hardening
- Block or warn on VBScript/WSH execution from user-writable and archive-extraction paths
- Alert on .NET processes spawning from %LOCALAPPDATA% with scheduled-task or Run-key persistence created within minutes
- Monitor C# loaders and DLLs launched from unusual parents and WMI Win32_Process creation by user-space .NET binaries
Timeline of UAC-0099 (MATCHBOIL) Downloader Gets Stealthier .NET Reactor
- CERT-UA first publicly reports UAC-0099 (activity dating to at least 2022) targeting Ukrainian government, financial and media organizations (day approximate: reported as June 2023).
- Earliest MATCHBOIL compilation window per ESET (samples compiled April 2024 - April 2026); 2024 builds use Unicode-symbol obfuscation and DeviceMonitor persistence (day approximate).
- Peak UAC-0099 phishing activity November-December 2024 against Ukrainian government, defense forces and defense industry (approximate date).
- C2 domain airarticlegenerate.com (64.95.13.210, BitLaunch VPS) first seen.
- ESET observes MATCHBOIL against multiple Ukrainian transportation companies (July-August 2025); builds persist via Run key only (day approximate).
- CERT-UA first documents MATCHBOIL, delivered by court-summons-themed phishing and deploying MATCHWOK and DRAGSTARE (day approximate).
- CERT-UA publicly documents MATCHBOIL, MATCHWOK and DRAGSTARE in a UAC-0099 phishing campaign (HTA-in-double-archive court-summons lures sent via UKR.NET) against Ukrainian government, defense and defense-industry targets.
- C2 domain telemetry-conf.com (Cloudflare-hidden) first seen.
- C2 domain virtualdailyplanner[.]pro first seen; late-2025 builds adopt Eziriz .NET Reactor, decoy daily-planner GUI, two-minute C2 timer and scheduled task UpdateCheckers\DailyPlanner.
- ESET observes MATCHBOIL against a Ukrainian manufacturing company (day approximate).
- ESET begins investigation after two VirusTotal samples (uploaded from Ukraine) contact a domain previously tied to UAC-0099; February builds add -plans/-renew arguments and a regex-utility decoy (day approximate).
- C2 domain flycloud-service.com (64.95.10.223, BitLaunch VPS) first seen.
- MATCHBOIL.V2: first DLL variant run by a custom C# loader, with OS install-date check and SMTPClient/MailClient\Checker persistence (day approximate).
- ESET observes MATCHBOIL against a Ukrainian energy-sector company (day approximate).
- CERT-UA warning (reported by The Hacker News, July 2026; month-level date) describes a MATCHBOIL.V2 chain using an image-attachment phishing email, link shortener, ZIP with a VBScript posing as a PDF, and a trojanized Notepad++ 8.8.3 bundle (LUNCHPOKE, BURNYBEAR) with a scheduled task running RemoteLibUpdater.exe every three minutes.
- ESET publishes GuardBreaker, describing a MATCHBOIL-delivering VBScript with a decoy comment requesting nuclear-weapon guidance, intended to trip LLM-based code-scanner guardrails (secondary coverage cites Aug 31/Sep 3, 2026; ESET page date used).
- ESET publishes 'MATCHBOIL: New tricks, same old evil intentions'; Dark Reading, The Record, Help Net Security and GovInfoSecurity cover it the same day.
Update history for TL-2026-3058
- 2026-10-09 — UAC-0099 upgrades MATCHBOIL downloader (MATCHBOIL.V2) in attacks on Ukrainian transport, manufacturing and energy firms: What changed No severity/exploitability/status change (already HIGH / ACTIVE). Additive intelligence only. New indicators (6) 1 new SHA1 from the ESET IOC table, filenames RemoteLibUpdater.exe, NppExport.dll and InitTest.dll, and malware fa
- 2026-10-09 — UAC-0099 (Russia-aligned) Evolves MATCHBOIL C# Downloader Targeting Ukraine: What changed No field escalation; severity HIGH, exploitability ACTIVE and status ACTIVE already reflect the evidence. New indicators (6) 6 new indicators: AnimalUpdate.exe, documenttemp.txt and temporarydoc.txt staging files, scheduled tas
- 2026-10-09 — MATCHBOIL Downloader Uses Cloudflare-Hidden C2 to Deliver MATCHWOK Backdoor (UAC-0099, Ukraine): What changed No severity, exploitability, status or attribution change; the record is enriched with additional context only. New indicators (4) 4 behavioral IOCs promoted from prose to indicators: mutex Global\PlannerAssistant and scheduled
Sources cited for UAC-0099 (MATCHBOIL) Downloader Gets Stealthier .NET Reactor
- MATCHBOIL: New tricks, same old evil intentions (ESET Research)
- Russian Spies Give 'MatchBoil' Malware a Stealthy Facelift (Dark Reading)
- Russian-aligned spies upgrade malware used in attacks on Ukrainian transport, energy firms (The Record)
- What is MATCHBOIL? The Russia-aligned malware that installs a spying backdoor (Help Net Security)
- Sandworm-Linked Group Sharpens Matchboil Downloader (GovInfoSecurity)
- ESET malware-ioc repository (MATCHBOIL IOCs)
- ESET press release: UAC-0099 intensifies attacks on Ukrainian industry with evolving MATCHBOIL downloader (GlobeNewswire)
- UAC-0099 Using WinRAR Exploit to Target Ukrainian Firms with LONEPAGE Malware (The Hacker News)
Detection coverage for TL-2026-3058
As of 2026-10-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3058 across Splunk SPL, Microsoft KQL and Sigma, covering 42 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-3058
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.