# UAC-0099 (MATCHBOIL) Downloader Gets Stealthier .NET Reactor Obfuscation, Sandbox Checks and Rotating Persistence in Attacks on Ukraine

> ESET research (published 2026-10-08) details the evolution of MATCHBOIL, a C# downloader used by the Russia-aligned UAC-0099 group to install the MATCHWOK C# backdoor on Ukrainian transportation, manufacturing and energy organizations. Samples compiled between April 2024 and April 2026 show a shift from a one-shot downloader to a repeating dropper with Eziriz .NET Reactor obfuscation, uptime and OS-age sandbox checks, decoy GUIs and changing persistence.

- **Published:** 2026-10-08T00:00:00Z
- **Last reviewed:** 2026-10-09T23:49:13.707Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3058
- **ID:** TL-2026-3058
- **Severity:** HIGH
- **Category:** APT
- **Status:** ACTIVE
- **Actor:** UAC-0099 (Russia)
- **Detections:** 9 · **IOCs:** 42 (full data via the Threadlinqs MCP server — Purple tier)

## Description

UAC-0099 is a cyber-espionage cluster tracked by CERT-UA since June 2023 and active since at least 2022, historically targeting Ukrainian government, financial and media organizations. ESET assesses with medium confidence that the group is aligned with Russian interests and that it may act as an initial access broker for Sandworm (APT44, GRU Unit 74455); no access hand-offs involving the observed victims were established. The group also uses LONEPAGE, a script downloader that CERT-UA has documented in WinRAR-exploit and LNK/HTA phishing chains.

Initial access is spear-phishing: the email carries a link to an archive containing a VBScript that the victim must run manually. The VBScript downloads and executes MATCHBOIL, a custom C# downloader. MATCHBOIL fingerprints the host (CPU ID, BIOS serial; later versions add username, MAC address of the first network interface, and computer model/manufacturer) and sends it in an SN HTTP header alongside a 25-character User-Agent. It performs three HTTPS requests: the first returns a numeric value reused in the second; the second returns HTML-like content from which a hex-encoded payload is extracted by a sample-specific regex (e.g. <script>(.*?)</script>) and hex-decoded; the third returns a string saved as a configuration file. The payload, usually the MATCHWOK C# backdoor (screenshots, PowerShell command execution), is written to a folder under %LOCALAPPDATA% (MATCHBOIL exits if the folder already exists) and set to relaunch via a scheduled task or Run key. The payload is started through WMI (Win32_Process via ManagementClass).

Evolution (ESET): 2024 samples use unprintable-Unicode class/method names and XOR/shift string encryption, drop to %LOCALAPPDATA%\DeviceMonitor and persist with the HKCU Run value DeviceMonitor plus scheduled task Updates\CheckTask, behaving as a one-shot downloader. July 2025 samples run async Tasks and persist only via the Run key. From November-December 2025 builds use Eziriz .NET Reactor (code virtualization, control-flow obfuscation), show a decoy daily-planner GUI when run without -auto, use mutex Global\PlannerAssistant, drop to %LOCALAPPDATA%\MeowCheck\MeowMeowProgramm.exe, poll the C2 on a two-minute timer and persist as scheduled task UpdateCheckers\DailyPlanner running every seven minutes. Sandbox checks read System event ID 6013 via EventLogReader, parse uptime in English and Russian, require at least three events showing >=7,200 s uptime, and test Debugger.IsAttached. Temporary files include WallpappersSet.jpg (Pictures) and config.library-ms (C:\Users\Public\Libraries). February 2026 builds add -plans and -renew arguments and a regex-search-utility decoy. An April 2026 variant (CERT-UA: MATCHBOIL.V2) is the first DLL form, run by a custom C# loader, adds an OS install-date check with a 10-day threshold, and drops %LOCALAPPDATA%\SMTPClient\SMTPClientApplication.exe persisted by scheduled task Checker under MailClient. A recent VBScript dropper persists a C# loader that runs MATCHBOIL.

ESET-observed victims were all in Ukraine: multiple transportation companies (July-August 2025), a manufacturer (December 2025) and an energy company (June 2026). Infrastructure is rented VPS (BitLaunch / BL Networks) and Cloudflare-fronted domains with non-reused Let's Encrypt certificates. CERT-UA's August 2025 reporting (as relayed by The Record) described court-summons-themed phishing against government, military and defense organizations, with MATCHBOIL deploying MATCHWOK and the DRAGSTARE infostealer. Caveat: Dark Reading returned HTTP 403, so facts derive from ESET's WeLiveSecurity report and secondary coverage; CERT-UA's advisories were not directly retrieved; BeaconBeagle returned 404 for both C2 IPs (no match data).

## MITRE ATT&CK

- T1566.002 Phishing: Spearphishing Link
- T1204.002 User Execution: Malicious File
- T1059.005 Command and Scripting Interpreter: Visual Basic
- T1047 Windows Management Instrumentation
- T1106 Native API
- T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
- T1053.005 Scheduled Task/Job: Scheduled Task
- T1497.001 Virtualization/Sandbox Evasion: System Checks
- T1622 Debugger Evasion
- T1140 Deobfuscate/Decode Files or Information
- T1113 Screen Capture
- T1071.001 Application Layer Protocol: Web Protocols
- T1132.001 Data Encoding: Standard Encoding
- T1573.002 Encrypted Channel: Asymmetric Cryptography
- T1583.001 Acquire Infrastructure: Domains
- T1583.003 Acquire Infrastructure: Virtual Private Server
- T1587.001 Develop Capabilities: Malware
- T1588.002 Obtain Capabilities: Tool
- T1027 Obfuscated Files or Information
- T1082 System Information Discovery
- T1105 Ingress Tool Transfer
- T1204.001 User Execution: Malicious Link
- T1059.001 Command and Scripting Interpreter: PowerShell
- T1678 Delay Execution
- T1036.005 Masquerading: Match Legitimate Resource Name or Location
- T1218.005 System Binary Proxy Execution: Mshta
- T1555.003 Credentials from Password Stores: Credentials from Web Browsers
- T1539 Steal Web Session Cookie
- T1005 Data from Local System

## Sources

- [MATCHBOIL: New tricks, same old evil intentions (ESET Research)](https://www.welivesecurity.com/en/eset-research/matchboil-new-tricks-same-old-evil-intentions/)
- [Russian Spies Give 'MatchBoil' Malware a Stealthy Facelift (Dark Reading)](https://www.darkreading.com/cyberattacks-data-breaches/russian-spies-matchboil-malware-facelift)
- [Russian-aligned spies upgrade malware used in attacks on Ukrainian transport, energy firms (The Record)](https://therecord.media/russia-ukraine-malware-transportation)
- [What is MATCHBOIL? The Russia-aligned malware that installs a spying backdoor (Help Net Security)](https://www.helpnetsecurity.com/2026/10/08/matchboil-malware-uac-0099/)
- [Sandworm-Linked Group Sharpens Matchboil Downloader (GovInfoSecurity)](https://www.govinfosecurity.com/sandworm-linked-group-sharpens-matchboil-downloader-a-33037)
- [ESET malware-ioc repository (MATCHBOIL IOCs)](https://github.com/eset/malware-ioc/tree/master/)
- [ESET press release: UAC-0099 intensifies attacks on Ukrainian industry with evolving MATCHBOIL downloader (GlobeNewswire)](https://www.globenewswire.com/news-release/2026/10/08/3377034/0/en/russian-aligned-uac-0099-intensifies-attacks-on-ukrainian-industry-with-evolving-matchboil-downloader.html)
- [UAC-0099 Using WinRAR Exploit to Target Ukrainian Firms with LONEPAGE Malware (The Hacker News)](https://thehackernews.com/search/label/Screenshot%20Malware)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3058
