The Russia-linked group UAC-0099 is continuously developing its C# downloader, MATCHBOIL. An analysis by ESET shows how the malware has been gradually hardened against detection and analysis since 2024. The focus is on improved obfuscation, changing persistence mechanisms and new methods for detecting sandbox environments.
MATCHBOIL acts as a downloader within the attack chain: the malware connects to the command-and-control infrastructure, downloads a further payload, installs it and ensures its persistence. In many of the cases analysed, this payload was the C# backdoor MATCHWOK, which is also attributed to UAC-0099.ESET attributes the group to Russian interests with a moderate degree of certainty. UAC-0099 specifically targets Ukrainian government organisations, financial institutions and media outlets, and may also act as an initial access broker for Sandworm. All MATCHBOIL victims observed by ESET were located in Ukraine. Those affected included companies in the transport, manufacturing and energy sectors, amongst others.
The infection chain typically begins with spear-phishing. Crafted links lead to archives containing VBScript files that download MATCHBOIL. Once executed, the malware collects device information, communicates with its C&C server and installs the subsequent payload. The technical evolution is particularly striking. Earlier variants functioned as one-off downloaders, whilst later versions repeat their C&C communication regularly, thereby enabling them to download new payloads. At the same time, obfuscation methods shifted from simple Unicode and string techniques to the commercial .NET Reactor. Anti-analysis functions were also added. Among other things, MATCHBOIL checks system runtimes, active debuggers and, in more recent variants, even the operating system’s installation date to detect potential sandbox or test environments. Disguise has also been improved with regard to users. Later versions display innocuous user interfaces and use more inconspicuous file and directory names. The analysis demonstrates one thing above all: malware becomes more dangerous not only through new functions, but through consistent optimisation. Changing persistence, better obfuscation and anti-analysis techniques make static detection and traditional signature-based methods more difficult.
For SOCs, this means placing greater emphasis on behavioural analysis, network telemetry and anomalies. MATCHBOIL serves as a prime example of how APT groups refine their tools over extended periods to establish access more reliably and keep it open for further operations.


