Decoding the world of cybersecurity

Russian-aligned UAC-0099 updates MATCHBOIL malware used against Ukrainian industry

ESET has traced changes to a downloader used by UAC-0099 against Ukrainian organisations, exposing sustained intrusion activity affecting industrial and essential-service environments.

Russian-aligned UAC-0099 updates MATCHBOIL malware used against Ukrainian industry
Summary
  • ESET identified newer MATCHBOIL variants using .NET Reactor obfuscation.
  • The malware downloads additional payloads and establishes persistence.
  • The observed victims were Ukrainian organisations across several sectors.

ESET has documented further development of MATCHBOIL, a downloader associated with Russia-aligned threat group UAC-0099, after observing attacks against organisations in Ukraine. The research describes changes to the software used to introduce additional malicious payloads and retain access to compromised systems.

The researchers observed targets across multiple Ukrainian sectors. Industrial operations, transport, and energy environments are relevant to the campaign, although the public evidence does not establish compromise of every organisation or site in those industries. ESET attributes the activity to UAC-0099 on the basis of its investigation and earlier tracking of the group.

MATCHBOIL is written in C# and communicates with infrastructure controlled by the attackers to obtain further payloads. By separating initial delivery from later activity, the downloader allows the operator to change the tools deployed after it obtains access. The software can also establish persistence, enabling continued operation across system restarts where its installation succeeds.

ESET found that newer versions use the .NET Reactor obfuscator. Obfuscation can hinder inspection of program logic by analysts and automated systems, although its presence alone does not establish that particular security products failed to detect the malware. The technique also complicates direct comparison between successive samples of the same threat family.

The group and its tools have a longer history than the latest research publication. CERT-UA publicly described MATCHBOIL in August 2025, while compilation timestamps led ESET to assess that development may have begun in April 2024. Compilation times can provide investigative clues, but they are not independent proof of the exact date a particular attack was conducted.

Because a downloader can deliver changing second-stage tools, an infection identified at one organisation may differ from another in the data accessed or actions taken. The available report establishes the capabilities of samples examined by ESET and the sectors represented in its telemetry; it does not provide a comprehensive victim count or confirmed consequences at every site.

Ukraine continues to experience cyber operations alongside physical attacks against energy and industrial infrastructure. The overlap places particular demands on incident investigation, since organisations may have to establish both whether digital systems were accessed and whether operational processes were affected. The malware evidence should not be taken as proof of physical disruption.

ESET’s report adds technical detail to a campaign that predates this week. The remaining uncertainty concerns the distribution of recent variants, the specific downstream payloads installed in individual cases, and the extent of access gained inside affected Ukrainian organisations.

In the reported campaign, the distinction between a downloader and a final payload is central. MATCHBOIL provides the route by which an operator can retrieve further software after gaining a foothold, so detection of the downloader does not by itself establish what happened subsequently on any particular compromised system. ESET’s description of a changing downloader documents attacker capability, rather than a complete inventory of successful intrusions.

Obfuscation introduces another operational complication. When developers conceal program logic behind commercial protection tools, static inspection becomes less straightforward, and defenders may have to combine behavioural observations with samples recovered from individual incidents. A change in protection technique can also cause older detection rules to become less effective even where the basic purpose of the malware remains familiar.

Ukraine’s industrial and transport organisations operate in an environment where the availability of supporting IT systems has direct operational consequences. Nevertheless, the research does not establish that this specific activity caused an interruption to a power station, factory or transport service. An infection aimed at an industrial company is not automatically a compromise of its operational technology.

The campaigns also sit within a wider pattern of persistent targeting of Ukrainian organisations during the war. Attribution to UAC-0099 is a research assessment based on observed tools and behaviour; it should not be confused with a public identification of every individual operator. Information about who was targeted and when must be read alongside the limits of what telemetry can show.

Recovery work in this kind of incident consequently involves more than removing the downloader. Investigators must establish whether second-stage code ran, what credentials and internal connections were available to the compromised account, and whether access survived the initial remediation. Those questions follow from the described mechanism, although ESET has not publicly resolved them for every victim.

×