Skip to content

Security2 publishersIndependently confirmed2 min readPublished

UAC-0099 pushes MATCHBOIL from Ukraine's transport firms into manufacturing and energy

UAC-0099, a Russia-aligned group, has pushed its MATCHBOIL downloader from Ukrainian transport firms into a manufacturer and an energy company, ESET says. The researchers tracked the tool for almost two years; it installs MATCHWOK, a C# backdoor that grabs screenshots and runs PowerShell.

The Watch · Security desk

How we use AISend a correction

Illustration accompanying UAC-0099 pushes MATCHBOIL from Ukraine's transport firms into manufacturing and energy
Generated illustration

What happened

  • The intrusion opens with a spear-phishing link that downloads an archive holding a VBScript, and that script fetches and runs MATCHBOIL.
  • MATCHBOIL fingerprints the host by its CPU ID and BIOS serial number, then makes three HTTPS requests to a server UAC-0099 controls.
  • The payload rides in the second HTTPS response as hex-encoded text inside HTML; MATCHBOIL writes it under %LOCALAPPDATA% and relaunches it via a scheduled task or registry key.
  • Early builds ran once and relied on persistence, but by late 2025 MATCHBOIL retried on a two-minute timer, so a failed first callback no longer killed the infection.
  • It screens for sandboxes by reading Windows event logs for uptime in English and Russian, running only when it finds at least three events showing two hours or more.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure MATCHBOIL's real deliverable is network access; ESET says that access may be useful to other groups, so one intrusion at a Ukrainian firm can seed operations beyond UAC-0099's own.
  • constraint By April 2026 the loader will not run unless the OS was installed at least ten days earlier, and its code is virtualized with Eziriz .NET Reactor, so a sample detonated in a fresh analysis VM can show nothing.
  • precedent These victims sit outside UAC-0099's known focus on government, finance and media, so Ukrainian industrial and infrastructure operators should treat this chain as aimed at them.

In 2024 the payload sat in a folder called DeviceMonitor. By late 2025 it was MeowMeowProgramm.exe inside a folder called MeowCheck, and by April 2026 it was SMTPClientApplication.exe inside SMTPClient, launched by a scheduled task named Checker under a directory called MailClient. [9] Those are the names to search for on a suspect host.

ESET attributes UAC-0099 to Russian interests with medium confidence, based on its targeting. [18] The expansion spanned about eleven months: transport companies in July and August 2025, a manufacturer in December, and an energy company in June 2026. [1][20]

Asked whether that signals a wider target list, ESET researcher Fernando Tavella pointed to the group's history. "UAC-0099 has been targeting different entities in Ukraine. We believe that the group has different interests and their expansion in the victimology could mean that they are seeking to maximise their impact in UA. Let's remember that this group has been an initial access broker of Sandworm, another Russia-aligned APT group, so it is possible they are seeking victims that can be of interest for other APT groups that UAC-0099 can assist." [16] An initial access broker breaks into networks and hands that foothold to someone else. [17]

Ukraine's CERT-UA documented MATCHBOIL in August 2025, but compilation timestamps in those samples point to mid-2024, so the tool was likely in use for roughly a year before it showed up in any public reporting. [19]

UAC-0099's servers are virtual machines leased from providers such as BitLaunch and hidden behind Cloudflare, and ESET found its Let's Encrypt certificates are not reused across domains. [15] The decoy shown to anyone who opens a sample by hand is a daily planner with a cat photo, its window titled "Dairy" and both text boxes labeled "Today." [14]

What to watch

  • Any victim outside Ukraine, which would break the all-Ukraine pattern in ESET's telemetry.
  • Observation of another APT such as Sandworm using a MATCHWOK foothold, which would confirm the reuse ESET flags.
  • The next filename and folder rotation after SMTPClient, Checker and MailClient, for refreshed hunting artifacts.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence68
Adoption
Insufficient
Hype gap+10
Incentives30
Confidence66
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    Every victim in ESET's telemetry was in Ukraine: transportation companies in July and August 2025, a manufacturer in December 2025, and an energy company in June 2026.

  2. [2]

    ESET traced almost two years of changes to MATCHBOIL, a downloader the Russia-aligned group UAC-0099 uses to plant a second program on Windows machines in Ukraine.

  3. [3]

    UAC-0099 has been described as going after government bodies, financial institutions, and media in Ukraine, so the transport, manufacturing, and energy victims are new.

Sources

2 independent publishers whose own reporting we read for this story.

  1. dev.to

    1 article · October 8, 2026

    MATCHBOIL: UAC-0099 Targets Ukrainian Organizations with Two-Minute C2 Polling and Sandbox Evasion
  2. helpnetsecurity.com

    1 article · October 8, 2026

    What is MATCHBOIL? The Russia-aligned malware that installs a spying backdoor

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Topics

Loading related stories