Threat reportAPTTL-2026-3058

UAC-0099 (MATCHBOIL) Downloader Gets Stealthier .NET Reactor Obfuscation, Sandbox Checks and Rotating Persistence in Attacks on Ukraine

highACTIVE

UAC-0099 (MATCHBOIL) Downloader Gets Stealthier .NET Reactor (TL-2026-3058), also tracked as MATCHBOIL, is a high-severity advanced persistent threat campaign, first published 2026-10-08 and last reviewed 2026-10-09. It is attributed to UAC-0099 (Russia) with medium confidence, affects Microsoft Windows, maps to 29 MITRE ATT&CK techniques (T1005, T1027, T1036.005), and is covered by 9 detection rules and 42 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
29MITRE ATT&CK
Actors
1UAC-0099
Detection rules
9SPL · KQL · Sigma
IOCs
42Indicators of compromise

Key facts for TL-2026-3058

Threat ID
TL-2026-3058
Also known as
MATCHBOIL, MATCHBOIL.V2, MATCHWOK
Severity
HIGH
Status
ACTIVE
Category
APT
First published
Last reviewed
Attribution
UAC-0099
Attribution confidence
MEDIUM
Nation-state nexus
Russia
Motivation
ESPIONAGE
Target sectors
transport, manufacturing, energy, government administration, defense, finance, news - media
Target regions
ukraine
Detection rules
9
Indicators of compromise
42
Updates
2026-10-09 · 3 updates · revalidated 3× · latest source

Malware and tooling in UAC-0099 (MATCHBOIL) Downloader Gets Stealthier .NET Reactor

Malware and tooling: DRAGSTARE, LONEPAGE, MATCHBOIL, MATCHWOK, Eziriz .NET Reactor

How UAC-0099 (MATCHBOIL) Downloader Gets Stealthier .NET Reactor works

ESET research (published 2026-10-08) details the evolution of MATCHBOIL, a C# downloader used by the Russia-aligned UAC-0099 group to install the MATCHWOK C# backdoor on Ukrainian transportation, manufacturing and energy organizations. Samples compiled between April 2024 and April 2026 show a shift from a one-shot downloader to a repeating dropper with Eziriz .NET Reactor obfuscation, uptime and OS-age sandbox checks, decoy GUIs and changing persistence.

UAC-0099 is a cyber-espionage cluster tracked by CERT-UA since June 2023 and active since at least 2022, historically targeting Ukrainian government, financial and media organizations. ESET assesses with medium confidence that the group is aligned with Russian interests and that it may act as an initial access broker for Sandworm (APT44, GRU Unit 74455); no access hand-offs involving the observed victims were established. The group also uses LONEPAGE, a script downloader that CERT-UA has documented in WinRAR-exploit and LNK/HTA phishing chains.

Initial access is spear-phishing: the email carries a link to an archive containing a VBScript that the victim must run manually. The VBScript downloads and executes MATCHBOIL, a custom C# downloader. MATCHBOIL fingerprints the host (CPU ID, BIOS serial; later versions add username, MAC address of the first network interface, and computer model/manufacturer) and sends it in an SN HTTP header alongside a 25-character User-Agent. It performs three HTTPS requests: the first returns a numeric value reused in the second; the second returns HTML-like content from which a hex-encoded payload is extracted by a sample-specific regex (e.g. <script>(.*?)</script>) and hex-decoded; the third returns a string saved as a configuration file. The payload, usually the MATCHWOK C# backdoor (screenshots, PowerShell command execution), is written to a folder under %LOCALAPPDATA% (MATCHBOIL exits if the folder already exists) and set to relaunch via a scheduled task or Run key. The payload is started through WMI (Win32_Process via ManagementClass).

Evolution (ESET): 2024 samples use unprintable-Unicode class/method names and XOR/shift string encryption, drop to %LOCALAPPDATA%\DeviceMonitor and persist with the HKCU Run value DeviceMonitor plus scheduled task Updates\CheckTask, behaving as a one-shot downloader. July 2025 samples run async Tasks and persist only via the Run key. From November-December 2025 builds use Eziriz .NET Reactor (code virtualization, control-flow obfuscation), show a decoy daily-planner GUI when run without -auto, use mutex Global\PlannerAssistant, drop to %LOCALAPPDATA%\MeowCheck\MeowMeowProgramm.exe, poll the C2 on a two-minute timer and persist as scheduled task UpdateCheckers\DailyPlanner running every seven minutes. Sandbox checks read System event ID 6013 via EventLogReader, parse uptime in English and Russian, require at least three events showing >=7,200 s uptime, and test Debugger.IsAttached. Temporary files include WallpappersSet.jpg (Pictures) and config.library-ms (C:\Users\Public\Libraries). February 2026 builds add -plans and -renew arguments and a regex-search-utility decoy. An April 2026 variant (CERT-UA: MATCHBOIL.V2) is the first DLL form, run by a custom C# loader, adds an OS install-date check with a 10-day threshold, and drops %LOCALAPPDATA%\SMTPClient\SMTPClientApplication.exe persisted by scheduled task Checker under MailClient. A recent VBScript dropper persists a C# loader that runs MATCHBOIL.

ESET-observed victims were all in Ukraine: multiple transportation companies (July-August 2025), a manufacturer (December 2025) and an energy company (June 2026). Infrastructure is rented VPS (BitLaunch / BL Networks) and Cloudflare-fronted domains with non-reused Let's Encrypt certificates. CERT-UA's August 2025 reporting (as relayed by The Record) described court-summons-themed phishing against government, military and defense organizations, with MATCHBOIL deploying MATCHWOK and the DRAGSTARE infostealer. Caveat: Dark Reading returned HTTP 403, so facts derive from ESET's WeLiveSecurity report and secondary coverage; CERT-UA's advisories were not directly retrieved; BeaconBeagle returned 404 for both C2 IPs (no match data).

MITRE ATT&CK techniques used in TL-2026-3058

Collection

T1005 Data from Local System; T1113 Screen Capture

Defense Evasion

T1027 Obfuscated Files or Information

Stealth

T1036.005 Masquerading: Match Legitimate Resource Name or Location; T1140 Deobfuscate/Decode Files or Information; T1218.005 System Binary Proxy Execution: Mshta; T1497.001 Virtualization/Sandbox Evasion: System Checks; T1622 Debugger Evasion; T1678 Delay Execution

Execution

T1047 Windows Management Instrumentation; T1059.001 Command and Scripting Interpreter: PowerShell; T1059.005 Command and Scripting Interpreter: Visual Basic; T1106 Native API; T1204.001 User Execution: Malicious Link; T1204.002 User Execution: Malicious File

Persistence

T1053.005 Scheduled Task/Job: Scheduled Task; T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder

Command and Control

T1071.001 Application Layer Protocol: Web Protocols; T1105 Ingress Tool Transfer; T1132.001 Data Encoding: Standard Encoding; T1573.002 Encrypted Channel: Asymmetric Cryptography

Discovery

T1082 System Information Discovery

Credential Access

T1539 Steal Web Session Cookie; T1555.003 Credentials from Password Stores: Credentials from Web Browsers

Initial Access

T1566.002 Phishing: Spearphishing Link

Resource Development

T1583.001 Acquire Infrastructure: Domains; T1583.003 Acquire Infrastructure: Virtual Private Server; T1587.001 Develop Capabilities: Malware; T1588.002 Obtain Capabilities: Tool

Affected products and versions in UAC-0099 (MATCHBOIL) Downloader Gets Stealthier .NET Reactor

  • Microsoft — Windows
    Vulnerable versions: Windows endpoints in targeted Ukrainian organizations (no specific versions reported)

Remediation for UAC-0099 (MATCHBOIL) Downloader Gets Stealthier .NET Reactor

Immediate actions

  • Block and sink the C2 domains and IPs listed in the IOC set; hunt proxy/DNS logs for historical contact
  • Hunt for %LOCALAPPDATA%\DeviceMonitor, \MeowCheck, \SMTPClient and scheduled tasks Updates\CheckTask, UpdateCheckers\DailyPlanner, MailClient\Checker
  • Quarantine mail links resolving to archives that contain .vbs files

Workarounds

  • Disable Windows Script Host for users who do not need it
  • Train staff in Ukrainian critical-infrastructure sectors on archive-with-script phishing lures

Longer-term hardening

  • Block or warn on VBScript/WSH execution from user-writable and archive-extraction paths
  • Alert on .NET processes spawning from %LOCALAPPDATA% with scheduled-task or Run-key persistence created within minutes
  • Monitor C# loaders and DLLs launched from unusual parents and WMI Win32_Process creation by user-space .NET binaries

Timeline of UAC-0099 (MATCHBOIL) Downloader Gets Stealthier .NET Reactor

  • CERT-UA first publicly reports UAC-0099 (activity dating to at least 2022) targeting Ukrainian government, financial and media organizations (day approximate: reported as June 2023).
  • Earliest MATCHBOIL compilation window per ESET (samples compiled April 2024 - April 2026); 2024 builds use Unicode-symbol obfuscation and DeviceMonitor persistence (day approximate).
  • Peak UAC-0099 phishing activity November-December 2024 against Ukrainian government, defense forces and defense industry (approximate date).
  • C2 domain airarticlegenerate.com (64.95.13.210, BitLaunch VPS) first seen.
  • ESET observes MATCHBOIL against multiple Ukrainian transportation companies (July-August 2025); builds persist via Run key only (day approximate).
  • CERT-UA first documents MATCHBOIL, delivered by court-summons-themed phishing and deploying MATCHWOK and DRAGSTARE (day approximate).
  • CERT-UA publicly documents MATCHBOIL, MATCHWOK and DRAGSTARE in a UAC-0099 phishing campaign (HTA-in-double-archive court-summons lures sent via UKR.NET) against Ukrainian government, defense and defense-industry targets.
  • C2 domain telemetry-conf.com (Cloudflare-hidden) first seen.
  • C2 domain virtualdailyplanner[.]pro first seen; late-2025 builds adopt Eziriz .NET Reactor, decoy daily-planner GUI, two-minute C2 timer and scheduled task UpdateCheckers\DailyPlanner.
  • ESET observes MATCHBOIL against a Ukrainian manufacturing company (day approximate).
  • ESET begins investigation after two VirusTotal samples (uploaded from Ukraine) contact a domain previously tied to UAC-0099; February builds add -plans/-renew arguments and a regex-utility decoy (day approximate).
  • C2 domain flycloud-service.com (64.95.10.223, BitLaunch VPS) first seen.
  • MATCHBOIL.V2: first DLL variant run by a custom C# loader, with OS install-date check and SMTPClient/MailClient\Checker persistence (day approximate).
  • ESET observes MATCHBOIL against a Ukrainian energy-sector company (day approximate).
  • CERT-UA warning (reported by The Hacker News, July 2026; month-level date) describes a MATCHBOIL.V2 chain using an image-attachment phishing email, link shortener, ZIP with a VBScript posing as a PDF, and a trojanized Notepad++ 8.8.3 bundle (LUNCHPOKE, BURNYBEAR) with a scheduled task running RemoteLibUpdater.exe every three minutes.
  • ESET publishes GuardBreaker, describing a MATCHBOIL-delivering VBScript with a decoy comment requesting nuclear-weapon guidance, intended to trip LLM-based code-scanner guardrails (secondary coverage cites Aug 31/Sep 3, 2026; ESET page date used).
  • ESET publishes 'MATCHBOIL: New tricks, same old evil intentions'; Dark Reading, The Record, Help Net Security and GovInfoSecurity cover it the same day.

Update history for TL-2026-3058

Sources cited for UAC-0099 (MATCHBOIL) Downloader Gets Stealthier .NET Reactor

Detection coverage for TL-2026-3058

As of 2026-10-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3058 across Splunk SPL, Microsoft KQL and Sigma, covering 42 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
42 indicators of compromise · Red and above. Compare plans

Community OSINT corroboration for TL-2026-3058

1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats