Security2 publishersIndependently confirmed2 min readPublished
UAC-0099 pushes MATCHBOIL from Ukraine's transport firms into manufacturing and energy
UAC-0099, a Russia-aligned group, has pushed its MATCHBOIL downloader from Ukrainian transport firms into a manufacturer and an energy company, ESET says. The researchers tracked the tool for almost two years; it installs MATCHWOK, a C# backdoor that grabs screenshots and runs PowerShell.
The Watch · Security desk

What happened
- The intrusion opens with a spear-phishing link that downloads an archive holding a VBScript, and that script fetches and runs MATCHBOIL.
- MATCHBOIL fingerprints the host by its CPU ID and BIOS serial number, then makes three HTTPS requests to a server UAC-0099 controls.
- The payload rides in the second HTTPS response as hex-encoded text inside HTML; MATCHBOIL writes it under %LOCALAPPDATA% and relaunches it via a scheduled task or registry key.
- Early builds ran once and relied on persistence, but by late 2025 MATCHBOIL retried on a two-minute timer, so a failed first callback no longer killed the infection.
- It screens for sandboxes by reading Windows event logs for uptime in English and Russian, running only when it finds at least three events showing two hours or more.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure MATCHBOIL's real deliverable is network access; ESET says that access may be useful to other groups, so one intrusion at a Ukrainian firm can seed operations beyond UAC-0099's own.
- constraint By April 2026 the loader will not run unless the OS was installed at least ten days earlier, and its code is virtualized with Eziriz .NET Reactor, so a sample detonated in a fresh analysis VM can show nothing.
- precedent These victims sit outside UAC-0099's known focus on government, finance and media, so Ukrainian industrial and infrastructure operators should treat this chain as aimed at them.
In 2024 the payload sat in a folder called DeviceMonitor. By late 2025 it was MeowMeowProgramm.exe inside a folder called MeowCheck, and by April 2026 it was SMTPClientApplication.exe inside SMTPClient, launched by a scheduled task named Checker under a directory called MailClient. [9] Those are the names to search for on a suspect host.
ESET attributes UAC-0099 to Russian interests with medium confidence, based on its targeting. [18] The expansion spanned about eleven months: transport companies in July and August 2025, a manufacturer in December, and an energy company in June 2026. [1][20]
Asked whether that signals a wider target list, ESET researcher Fernando Tavella pointed to the group's history. "UAC-0099 has been targeting different entities in Ukraine. We believe that the group has different interests and their expansion in the victimology could mean that they are seeking to maximise their impact in UA. Let's remember that this group has been an initial access broker of Sandworm, another Russia-aligned APT group, so it is possible they are seeking victims that can be of interest for other APT groups that UAC-0099 can assist." [16] An initial access broker breaks into networks and hands that foothold to someone else. [17]
Ukraine's CERT-UA documented MATCHBOIL in August 2025, but compilation timestamps in those samples point to mid-2024, so the tool was likely in use for roughly a year before it showed up in any public reporting. [19]
UAC-0099's servers are virtual machines leased from providers such as BitLaunch and hidden behind Cloudflare, and ESET found its Let's Encrypt certificates are not reused across domains. [15] The decoy shown to anyone who opens a sample by hand is a daily planner with a cat photo, its window titled "Dairy" and both text boxes labeled "Today." [14]
What to watch
- Any victim outside Ukraine, which would break the all-Ukraine pattern in ESET's telemetry.
- Observation of another APT such as Sandworm using a MATCHWOK foothold, which would confirm the reuse ESET flags.
- The next filename and folder rotation after SMTPClient, Checker and MailClient, for refreshed hunting artifacts.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap+10
- Incentives30
- Confidence66
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Every victim in ESET's telemetry was in Ukraine: transportation companies in July and August 2025, a manufacturer in December 2025, and an energy company in June 2026.
- [2]
ESET traced almost two years of changes to MATCHBOIL, a downloader the Russia-aligned group UAC-0099 uses to plant a second program on Windows machines in Ukraine.
- [3]
UAC-0099 has been described as going after government bodies, financial institutions, and media in Ukraine, so the transport, manufacturing, and energy victims are new.
- [4]
The program MATCHBOIL installs is a spying tool, and the access it creates may be useful to other groups.
- [5]
MATCHBOIL downloads a C# backdoor called MATCHWOK that can take screenshots of the victim's desktop and execute PowerShell commands, ESET researcher Fernando Tavella said.
ReportedSupportedSource: Fernando Tavella, ESET researcher, to Help Net Security2 sources— create a free account to open themView cited source - [6]
The delivery chain starts with a link in a spear-phishing email; the link downloads an archive holding a VBScript file, which downloads and runs MATCHBOIL.
- [7]
MATCHBOIL fingerprints the machine using its CPU ID and BIOS serial number, then makes three HTTPS requests to the group's server.
- [8]
The second HTTPS response is HTML with the payload hidden inside as hex-encoded text; MATCHBOIL extracts it, writes it to a folder under %LOCALAPPDATA%, and sets it to relaunch through a scheduled task or a Windows registry key. If that folder already exists, MATCHBOIL exits.
- [9]
The payload's hiding place moved over time: a folder called DeviceMonitor in 2024, MeowMeowProgramm.exe in a folder called MeowCheck by late 2025, and SMTPClientApplication.exe in a folder called SMTPClient by April 2026, with a scheduled task named Checker under a directory named MailClient.
- [10]
Early versions of MATCHBOIL ran once and relied on the persistence setting; by late 2025 it ran on a two-minute timer, so a failed first contact with the server no longer ended the infection.
- [11]
MATCHBOIL swapped its homemade string scrambling for a commercial obfuscator, Eziriz .NET Reactor, which can virtualize code and tangle its control flow.
- [12]
MATCHBOIL screens for sandboxes by reading Windows event logs for system uptime, searching in English and Russian, and runs only if it finds at least three events showing 7,200 seconds (two hours) or more.
- [13]
The April 2026 version added a second test: it checks whether the operating system was installed at least ten days before the malware runs.
- [14]
Late 2025 builds show a daily planner with a cat photo to anyone who launches them by hand; the window is titled "Dairy" and both text boxes are labeled "Today."
- [15]
UAC-0099 rents virtual servers from providers such as BitLaunch and puts Cloudflare in front of them; ESET found its Let's Encrypt certificates are not reused across domains.
- [16]
UAC-0099 has been targeting different entities in Ukraine. We believe that the group has different interests and their expansion in the victimology could mean that they are seeking to maximise their impact in UA. Let's remember that this group has been an initial access broker of Sandworm, another Russia-aligned APT group, so it is possible they are seeking victims that can be of interest for other APT groups that UAC-0099 can assist.
- [17]
An initial access broker breaks into networks and hands that foothold to someone else.
- [18]
ESET attributes UAC-0099 to Russian interests with medium confidence, based on its targeting.
- [19]
Ukraine's CERT-UA documented MATCHBOIL in August 2025; compilation timestamps in those samples point to mid-2024, meaning the tool likely ran for about a year before anyone published on it.
- [20]
The span of ESET's dated victims, from the transport companies in July 2025 to the energy company in June 2026, is about eleven months.
Sources
2 independent publishers whose own reporting we read for this story.
- dev.toMATCHBOIL: UAC-0099 Targets Ukrainian Organizations with Two-Minute C2 Polling and Sandbox Evasion
1 article · October 8, 2026
- helpnetsecurity.comWhat is MATCHBOIL? The Russia-aligned malware that installs a spying backdoor
1 article · October 8, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- Ukraine cyber conflictFollow
- Sandbox Evasion and Connectivity GatingFollow
- Cyber EspionageFollow
- Initial Access BrokersFollow