Security2 publishersIndependently confirmed2 min readPublished
ESET traces at least 21 months of changes to UAC-0099's MatchBoil downloader
ESET says UAC-0099 has reworked its MatchBoil downloader since at least July 2024, with the newest version appearing in April 2026. Repeated changes aimed at security software mean indicators from CERT-UA's August 2025 write-up describe an older build.
The Watch · Security desk
What happened
- ESET found MatchBoil at several Ukrainian transport companies in July and August 2025, at a manufacturer in December 2025 and at an energy-sector company in June 2026.
- The malware arrives through links in phishing emails, and a click downloads an archive whose files end up running MatchBoil on the victim's computer.
- Once running, MatchBoil profiles the machine, pulls further malware from an attacker-controlled server and sets up persistence.
- In August 2025 CERT-UA reported the group mailing fake Ukrainian court summonses to government, military and defense organizations as part of an espionage campaign.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- cost Defense sits at mail link handling and at what is allowed to execute from a downloaded archive; there is no vendor patch to wait on, because the chain ESET describes uses no exploit.
- exposure If UAC-0099 reuses its 2025 follow-on payloads, one click at a Ukrainian manufacturer or energy firm can end with a remote-command backdoor and a stealer taking browser passwords and cookies.
- exposure Every infection ESET has observed is in Ukraine, so for operators in the same industries elsewhere this report shows a sector match and no observed targeting.
The move into new sectors rests on small numbers. ESET's account lists several transport companies, then one manufacturer and one energy company [17]. Neither ESET nor CERT-UA has said how many organizations or individuals UAC-0099 has compromised [15].
The development record is the firmer finding. ESET's start date puts work on MatchBoil about 13 months ahead of CERT-UA's first public documentation in August 2025 [5][19]. Besides making the malware harder to detect and analyze, the group improved how it deceives victims and widened what it collects about infected machines, according to ESET [7]. "Each new iteration of the downloader was more sophisticated than the last, showing that MatchBoil is an important part of the group's toolkit," ESET researchers said [9].
A variant found in late 2025 shows a fake daily planner when a victim opens MatchBoil by hand, apparently to make the program look legitimate [10]. The planner has two fields both labeled "Today", and a typo in its window title makes it look like a tool for planning milk consumption [10].
The tool belongs to a long-running operation. UAC-0099 has been active since at least 2022 and was first reported publicly by CERT-UA in June 2023 [11]. Its main targets have been Ukrainian government bodies, financial institutions and media outlets [11]. The transport, manufacturing and energy detections add industries to that list [3]. ESET's attribution is hedged: it says the group is likely working in Russia's interests [1]. Its researchers read the pace of MatchBoil's changes as a sign the group will keep developing it for future operations [8].
What to watch
- Published indicators for the April 2026 build, and confirmation of which build ESET found at the energy company in June 2026.
- A victim count from ESET or CERT-UA, which would show whether the single manufacturing and energy detections are isolated or part of a wider push.
- Any MatchBoil infection outside Ukraine, which would put operators elsewhere inside the observed target set.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+15
- Incentives
- Insufficient
- Confidence62
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
MatchBoil is used by UAC-0099, a cyberespionage group that ESET believes is likely working in Russia's interests; ESET published its report on Thursday.
ReportedSupportedSource: ESET, via The Record2 sources— create a free account to open themView cited source - [2]
ESET said all MatchBoil infections it has observed were in Ukraine.
ReportedSupportedSource: ESET, via The Record2 sources— create a free account to open themView cited source - [3]
Researchers detected MatchBoil at several transportation companies between July and August 2025, at a manufacturing company in December 2025 and at an energy-sector company in June 2026.
ReportedSupportedSource: ESET, via The Record2 sources— create a free account to open themView cited source - [4]
MatchBoil can collect information about the infected machine, download additional malicious software from an attacker-controlled server and establish persistence.
ReportedSupportedSource: The Record, citing ESET2 sources— create a free account to open themView cited source - [5]
CERT-UA first publicly documented MatchBoil in August 2025.
- [6]
ESET's analysis shows MatchBoil had been under development since at least July 2024, with a newer version appearing as recently as April 2026.
ReportedSupportedSource: ESET, via The Record2 sources— create a free account to open themView cited source - [7]
The hackers repeatedly modified MatchBoil to make it harder for security software to detect and analyze, improve how it deceives victims and gather more information about infected computers.
ReportedSupportedSource: ESET, via The Record2 sources— create a free account to open themView cited source - [8]
ESET researchers said the pace of the changes suggests UAC-0099 considers MatchBoil an important part of its arsenal and is continuing to develop it for future operations.
ReportedSupportedSource: ESET researchers, via The Record2 sources— create a free account to open themView cited source - [9]
"Each new iteration of the downloader was more sophisticated than the last, showing that MatchBoil is an important part of the group's toolkit,"
ReportedSupportedSource: ESET researchers, quoted by The Record2 sources— create a free account to open themView cited source - [10]
A variant discovered in late 2025 adds a fake daily planner that appears if a victim manually opens MatchBoil, apparently to make the program look legitimate; the planner has two fields both labeled "Today" and a typo in its window title makes it appear designed for planning milk consumption.
ReportedSupportedSource: The Record, citing ESET2 sources— create a free account to open themView cited source - [11]
UAC-0099 has been active since at least 2022, was first publicly reported by CERT-UA in June 2023, and has primarily targeted Ukrainian government organizations, financial institutions and media outlets.
- [12]
MatchBoil is typically delivered through malicious links in phishing emails; clicking a link downloads an archive containing files that ultimately execute the malware on the victim's computer.
- [13]
In August 2025, CERT-UA said the group had sent phishing emails disguised as Ukrainian court summonses as part of an espionage campaign targeting government, military and defense organizations.
- [14]
In that operation MatchBoil gathered information about compromised computers and deployed the MatchWok backdoor, which lets attackers remotely execute commands, and the Dragstare information stealer, which can extract browser passwords and cookies and files on the victim's desktop.
- [15]
Neither ESET nor CERT-UA has disclosed how many organizations or individuals have been compromised by UAC-0099.
- [16]
ESET's record of MatchBoil development spans at least 21 months.
- [17]
Manufacturing and energy are each represented by a single detection in ESET's account.
- [18]
The delivery chain as described depends on a recipient clicking an emailed link and files from the downloaded archive executing; the described chain involves no software exploit.
- [19]
ESET's earliest development date for MatchBoil precedes CERT-UA's first public documentation by about 13 months.
Sources
2 independent publishers whose own reporting we read for this story.
- infosecurity-magazine.comRussia-Aligned UAC-0099 Evolves MATCHBOIL Malware
1 article · October 8, 2026
- therecord.mediaRussian-aligned spies upgrade malware used in attacks on Ukrainian transport, energy firms
1 article · October 8, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.