Threat Intelligence, Malware

Sophisticated malware downloader MatchBoil targets Ukrainian organizations

Laptop screen showing malware warning sign with digital circuit background on desk in modern office environment with natural light and creative concept.

A likely Russia-affiliated cyber-espionage group, identified as UAC-0099, is employing an increasingly sophisticated malware downloader named MatchBoil to target Ukrainian organizations across critical sectors, according to a recent report by Dark Reading.

MatchBoil is designed to deliver MatchWok, a C# backdoor that provides persistent access to compromised systems. Since at least 2024, the malware has undergone continuous development, enhancing its obfuscation techniques, sandbox evasion capabilities, and persistence mechanisms. Initially targeting transportation companies, UAC-0099 has expanded its focus to include the manufacturing and energy sectors. Attacks typically begin with spear-phishing emails containing a VBScript payload. Once executed, MatchBoil checks for specific system conditions before communicating with its command-and-control server to download further payloads. The group's efforts to refine MatchBoil, including the use of commercial obfuscation tools and evolving persistence strategies, indicate a strong interest in evading security solutions and maintaining a foothold for future operations. ESET suggests UAC-0099 may serve as an initial access broker for the Sandworm threat actor, which is linked to Russian military intelligence.

Source: Dark Reading

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds