Skip to content

Image: web-assets.esetstatic.com · rights & removal

Executive Summary

The evolution of the MATCHBOIL malware, a C# downloader used by the UAC-0099 group, spans from April 2024 to April 2026, demonstrating continuous refinement by the threat actor. The initial versions utilized Unicode symbol renaming and custom string encryption, employing a one-shot download mechanism and persistence via scheduled tasks or registry entries. Subsequent iterations introduced significant changes, including the adoption of the Eziriz .NET Reactor obfuscator, asynchronous task execution, and more sophisticated defense evasion techniques such as checking for sandbox environments using Windows event logs. The malware's C&C communication has evolved, incorporating new HTTP header formats to signal payload requests, and persistence methods have shifted between registry modifications and scheduled tasks. Furthermore, the malware has developed mechanisms for user deception, including the introduction of a graphical user interface (GUI). The observed samples suggest a continuous effort by UAC-0099 to enhance its toolkit for future operations across various sectors in Ukraine.

Facts Only

* MATCHBOIL is a C# downloader used by UAC-0099 to download, install, and persist another payload.
* Analysis covers samples from April 2024 to April 2026.
* Early samples used Unicode symbol renaming and custom XOR/bitwise shift encryption for strings.
* The initial payload installation involved checking for directory existence in %LOCALAPPDATA% before initiating HTTPS requests.
* C&C communication involves three HTTPS requests, using dynamic HTTP headers (like SN and Count) and extracting hex-encoded payloads from HTML responses.
* The installed payload is typically a C# backdoor named MATCHWOK.
* Persistence mechanisms included registry values in the Run key and scheduled tasks.
* Later versions switched to using the Eziriz .NET Reactor obfuscator.
* Logic evolved from a one-shot download to execution on a two-minute timer by the end of 2025.
* Defense evasion techniques were introduced to check for sandbox environments via Windows event logs.
* The latest variant in April 2026 involved installing payloads under %LOCALAPPDATA%\SMTPClient and using a scheduled task named Checker for persistence.

Full Take

The trajectory of MATCHBOIL reveals a clear pattern of adaptive hardening against analysis and detection, driven by the operational demands of UAC-0099. The progression from simple XOR encryption in 2024 to the complex control flow obfuscation via .NET Reactor in late 2025 signifies a shift from basic functionality to sophisticated stealth engineering. This evolution suggests that the threat actor views the malware not just as a tool, but as an evolving component of a persistent attack framework where minimizing forensic artifacts is paramount. The introduction of GUI elements and sandbox detection logic demonstrates a pattern focused on operational security and evading automated analysis environments.
The pattern observed is one of iterative improvement predicated on perceived risk. When initial methods are successfully countered by defenders or security tools, the actor pivots to more advanced techniques—changing obfuscation schemes, modifying persistence mechanisms based on environmental context (e.g., checking system uptime), and refining C&C interaction. This implies that the motivation for each evolution is not singular; it is the continuous optimization of the malware’s lifecycle within a hostile environment. The shift in payload naming (from DeviceMonitor to SMTPClientApplication) further reinforces an intent to obscure the ultimate objective and improve camouflage, suggesting that the sequence of changes reflects a deliberate hardening process rather than random iteration.
The implications for cognitive sovereignty lie in recognizing this systemic adaptation: adversaries treat security measures as obstacles to be bypassed or integrated into their toolset. The focus shifts from analyzing individual code blocks to understanding the macro-strategy behind the toolset's continuous refinement—how attackers leverage incremental changes to ensure long-term operational viability and resilience against evolving defensive paradigms. What processes are in place to analyze and counter such persistent, low-level developmental evolution?

From the original · ESET Research

ESET researchers have documented the evolution of the MATCHBOIL malware, a custom C# downloader wielded by the Russia-aligned UAC-0099 APT group. The malware is used to download a payload from the group’s C&C server, install it, and establish its persistence.
Read the full story at welivesecurity.com

Sentinel — Human

Confidence

The text appears to be a detailed security research summary derived from forensic analysis, characterized by structured technical enumeration and temporal progression, rather than purely synthetic generation.

Signals Detected
low severity: Moderate sentence length variance and detailed technical enumeration suggest human synthesis, though the flow is highly structured.
low severity: The text maintains a clear, focused trajectory based on chronological malware evolution, demonstrating cohesive narrative structure despite dense technical detail.
low severity: The presentation of specific file hashes, timestamps, and structured lists (especially the MITRE ATT&CK mapping) suggests highly curated, source-driven compilation rather than pure LLM generation.
low severity: The high density of very specific technical details (obfuscators, specific registry keys, C&C protocol steps) implies deep domain knowledge; however, the chronological jumps and reliance on aggregated telemetry suggest careful assembly rather than raw fabrication.
Human Indicators
The analysis weaves together very specific, evolving technical details (e.g., code obfuscation changes across years) in a manner that suggests an internal forensic investigation was summarized.
Use of source attribution (ESET telemetry, CERT-UA) anchors the claims to external data points.
MATCHBOIL: New tricks, same old evil intentions | Huntaegis