Skip to content

Security2 publishersIndependently confirmed2 min readPublished

ESET traces at least 21 months of changes to UAC-0099's MatchBoil downloader

ESET says UAC-0099 has reworked its MatchBoil downloader since at least July 2024, with the newest version appearing in April 2026. Repeated changes aimed at security software mean indicators from CERT-UA's August 2025 write-up describe an older build.

The Watch · Security desk

How we use AISend a correction

What happened

  • ESET found MatchBoil at several Ukrainian transport companies in July and August 2025, at a manufacturer in December 2025 and at an energy-sector company in June 2026.
  • The malware arrives through links in phishing emails, and a click downloads an archive whose files end up running MatchBoil on the victim's computer.
  • Once running, MatchBoil profiles the machine, pulls further malware from an attacker-controlled server and sets up persistence.
  • In August 2025 CERT-UA reported the group mailing fake Ukrainian court summonses to government, military and defense organizations as part of an espionage campaign.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • cost Defense sits at mail link handling and at what is allowed to execute from a downloaded archive; there is no vendor patch to wait on, because the chain ESET describes uses no exploit.
  • exposure If UAC-0099 reuses its 2025 follow-on payloads, one click at a Ukrainian manufacturer or energy firm can end with a remote-command backdoor and a stealer taking browser passwords and cookies.
  • exposure Every infection ESET has observed is in Ukraine, so for operators in the same industries elsewhere this report shows a sector match and no observed targeting.

The move into new sectors rests on small numbers. ESET's account lists several transport companies, then one manufacturer and one energy company [17]. Neither ESET nor CERT-UA has said how many organizations or individuals UAC-0099 has compromised [15].

The development record is the firmer finding. ESET's start date puts work on MatchBoil about 13 months ahead of CERT-UA's first public documentation in August 2025 [5][19]. Besides making the malware harder to detect and analyze, the group improved how it deceives victims and widened what it collects about infected machines, according to ESET [7]. "Each new iteration of the downloader was more sophisticated than the last, showing that MatchBoil is an important part of the group's toolkit," ESET researchers said [9].

A variant found in late 2025 shows a fake daily planner when a victim opens MatchBoil by hand, apparently to make the program look legitimate [10]. The planner has two fields both labeled "Today", and a typo in its window title makes it look like a tool for planning milk consumption [10].

The tool belongs to a long-running operation. UAC-0099 has been active since at least 2022 and was first reported publicly by CERT-UA in June 2023 [11]. Its main targets have been Ukrainian government bodies, financial institutions and media outlets [11]. The transport, manufacturing and energy detections add industries to that list [3]. ESET's attribution is hedged: it says the group is likely working in Russia's interests [1]. Its researchers read the pace of MatchBoil's changes as a sign the group will keep developing it for future operations [8].

What to watch

  • Published indicators for the April 2026 build, and confirmation of which build ESET found at the energy company in June 2026.
  • A victim count from ESET or CERT-UA, which would show whether the single manufacturing and energy detections are isolated or part of a wider push.
  • Any MatchBoil infection outside Ukraine, which would put operators elsewhere inside the observed target set.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence58
Adoption
Insufficient
Hype gap+15
Incentives
Insufficient
Confidence62
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    MatchBoil is used by UAC-0099, a cyberespionage group that ESET believes is likely working in Russia's interests; ESET published its report on Thursday.

    ReportedSupportedSource: ESET, via The Record2 sources— create a free account to open themView cited source
  2. [2]

    ESET said all MatchBoil infections it has observed were in Ukraine.

    ReportedSupportedSource: ESET, via The Record2 sources— create a free account to open themView cited source
  3. [3]

    Researchers detected MatchBoil at several transportation companies between July and August 2025, at a manufacturing company in December 2025 and at an energy-sector company in June 2026.

    ReportedSupportedSource: ESET, via The Record2 sources— create a free account to open themView cited source

Sources

2 independent publishers whose own reporting we read for this story.

  1. infosecurity-magazine.com

    1 article · October 8, 2026

    Russia-Aligned UAC-0099 Evolves MATCHBOIL Malware
  2. therecord.media

    1 article · October 8, 2026

    Russian-aligned spies upgrade malware used in attacks on Ukrainian transport, energy firms

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Topics

Entities

Loading related stories