MATCHBOIL downloader evolution by UAC-0099
Malware Activity
Summary
Hide ▲
Show ▼
UAC-0099 has steadily upgraded MATCHBOIL, a C# downloader used against Ukrainian organizations, increasing obfuscation, adding sandbox checks, and changing execution and persistence behavior. The activity matters because the malware has been observed across transportation, manufacturing, and energy and continued through June 2026.
Related Happenings
UAC-0145 / Sandworm ClickFix campaign targeting Ukrainian targets
Campaign
H score24
First: 19.07.2026 16:30
Last: 19.07.2026 16:30
Sources 1
About this happening:
Sandworm-linked UAC-0145 is running a ClickFix campaign that uses compromised websites and fake CAPTCHA lures to push Ukrainian targets into executing atta...
UAC-0145 / Sandworm ClickFix campaign targeting Ukrainian targets
CampaignAbout this happening: Sandworm-linked UAC-0145 is running a ClickFix campaign that uses compromised websites and fake CAPTCHA lures to push Ukrainian targets into executing atta...
Timeline
-
08.10.2026 16:00 2 articles · 8h ago
ESET documents UAC-0099’s evolving MATCHBOIL downloader
Technical Analysis UpdateESET documented MATCHBOIL variants compiled or observed between April 2024 and April 2026, saying each version became more sophisticated. The research tied the C# downloader to UAC-0099, described stronger obfuscation, sandbox checks, shifting execution behavior and persistence changes, and said MATCHBOIL activity had been seen in Ukraine across transportation, manufacturing and energy as recently as June 2026.
Show sources
- Russia-Aligned UAC-0099 Evolves MATCHBOIL Malware — www.infosecurity-magazine.com — 08.10.2026 16:00
- Russia-Aligned UAC-0099 Evolves MATCHBOIL Malware — www.infosecurity-magazine.com — 08.10.2026 16:00