A likely Russia-affiliated cyber-espionage group, identified as UAC-0099, is employing an increasingly sophisticated malware downloader named MatchBoil to target Ukrainian organizations across critical sectors, according to a recent report by Dark Reading.
MatchBoil is designed to deliver MatchWok, a C# backdoor that provides persistent access to compromised systems. Since at least 2024, the malware has undergone continuous development, enhancing its obfuscation techniques, sandbox evasion capabilities, and persistence mechanisms. Initially targeting transportation companies, UAC-0099 has expanded its focus to include the manufacturing and energy sectors. Attacks typically begin with spear-phishing emails containing a VBScript payload. Once executed, MatchBoil checks for specific system conditions before communicating with its command-and-control server to download further payloads. The group's efforts to refine MatchBoil, including the use of commercial obfuscation tools and evolving persistence strategies, indicate a strong interest in evading security solutions and maintaining a foothold for future operations. ESET suggests UAC-0099 may serve as an initial access broker for the Sandworm threat actor, which is linked to Russian military intelligence.
Source: Dark Reading
