<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/russian-spies-give-matchboil-malware-a-stealthy-facelift-nu7j4gk9z" -->

---
title: Russian Spies Give 'MatchBoil' Malware a Stealthy Facelift
description: A Russia-aligned threat actor tracked as UAC-0099 has been continuously upgrading its MatchBoil malware downloader since 2024, according to ESET research, to...
canonical: https://daily.dev/posts/russian-spies-give-matchboil-malware-a-stealthy-facelift-nu7j4gk9z
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Russian Spies Give 'MatchBoil' Malware a Stealthy Facelift | daily.dev
og:description: A Russia-aligned threat actor tracked as UAC-0099 has been continuously upgrading its MatchBoil malware downloader since 2024, according to ESET research, to...
og:url: https://daily.dev/posts/russian-spies-give-matchboil-malware-a-stealthy-facelift-nu7j4gk9z
og:image: https://api.daily.dev/og/posts/nu7j4gK9z.png
og:image:alt: Russian Spies Give 'MatchBoil' Malware a Stealthy Facelift
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Russian Spies Give 'MatchBoil' Malware a Stealthy Facelift

**[Dark Reading](https://daily.dev/sources/dr)** · 4 min read · 1 upvotes · 0 comments

## Summary

A Russia-aligned threat actor tracked as UAC-0099 has been continuously upgrading its MatchBoil malware downloader since 2024, according to ESET research, to target Ukrainian transportation, manufacturing, and energy organizations. MatchBoil delivers a C# backdoor called MatchWok and has evolved from a one-shot downloader into a dropper that executes every two minutes to repeatedly fetch updated payloads. Recent versions add Eziriz .NET Reactor obfuscation, sandbox evasion checks, and shifting persistence mechanisms (registry keys, Run key, scheduled tasks). ESET assesses with moderate confidence that UAC-0099 acts as an initial access broker for Sandworm, the Russian military intelligence-linked group behind destructive attacks on Ukraine's power grid.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.darkreading.com/cyberattacks-data-breaches/russian-spies-matchboil-malware-facelift>

## Questions this post answers

### What is MatchBoil malware and who is behind it?

MatchBoil is a malware downloader used by the threat actor UAC-0099, a group believed with moderate confidence to be linked to Russian interests. It delivers a C# backdoor called MatchWok that gives attackers persistent access to compromised systems. The group targets Ukrainian transportation, manufacturing, and energy organizations and is believed to act as an initial access broker for Sandworm.

_Security teams tracking Russia-linked threat actors can follow malware campaign developments like MatchBoil on daily.dev._

### How has UAC-0099's MatchBoil downloader evolved to evade detection?

MatchBoil shifted from basic Unicode-based obfuscation in 2024 to commercial Eziriz .NET Reactor obfuscation by 2026, alongside added sandbox checks and a less conspicuous interface. Its persistence mechanism also changed repeatedly, moving from registry values and scheduled tasks to the Windows Run key, then back to scheduled tasks. By late 2025 it began executing every two minutes to repeatedly fetch updated payloads from its command-and-control server.

_Defenders hardening against evasive droppers can track evolving obfuscation and persistence tactics on daily.dev._

### How do UAC-0099 spear-phishing attacks initially infect victims?

Attacks typically begin with spear-phishing emails containing a link to an archive file with a VBScript payload. Victims who download and manually execute the script end up with MatchBoil installed. The malware then checks for a specific directory and terminates if it already exists, then gathers machine details used to identify the victim during subsequent command-and-control communications.

_Incident responders studying phishing-delivered droppers can follow similar threat writeups on daily.dev._

## Similar posts on daily.dev

- [From Phishing to Malware: AI Becomes Russia's New Cyber Weapon in War on Ukraine](https://daily.dev/posts/from-phishing-to-malware-ai-becomes-russia-s-new-cyber-weapon-in-war-on-ukraine-jdqsub135) · The Hacker News · 0 upvotes · 0 comments
- [Russia's 'Gamaredon' Upgrades Its Arsenal, Requiring New Defenses](https://daily.dev/posts/russia-s-gamaredon-upgrades-its-arsenal-requiring-new-defenses-4n9dt8v9w) · Dark Reading · 0 upvotes · 0 comments
- [11 Malicious NuGet Tools Pose as Game Cheats to Drop a Windo...](https://daily.dev/posts/11-malicious-nuget-tools-pose-as-game-cheats-to-drop-a-windo--rraw5qijj) · Socket · 0 upvotes · 0 comments
- [Wipers from Russia’s most cut-throat hackers rain destruction on Ukraine](https://daily.dev/posts/wipers-from-russia-s-most-cut-throat-hackers-rain-destruction-on-ukraine-j7pibbj7x) · Ars Technica · 1 upvotes · 0 comments
- [Trojanized ESET Installers Drop Kalambur Backdoor in Phishing Attacks on Ukraine](https://daily.dev/posts/trojanized-eset-installers-drop-kalambur-backdoor-in-phishing-attacks-on-ukraine-amw6o2ru1) · The Hacker News · 1 upvotes · 0 comments

---

Tags: [#malware](https://daily.dev/tags/malware)

[View this post on daily.dev](https://daily.dev/posts/russian-spies-give-matchboil-malware-a-stealthy-facelift-nu7j4gk9z)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Russian Spies Give 'MatchBoil' Malware a Stealthy Facelift","url":"https://daily.dev/posts/russian-spies-give-matchboil-malware-a-stealthy-facelift-nu7j4gk9z","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/russian-spies-give-matchboil-malware-a-stealthy-facelift-nu7j4gk9z"},"datePublished":"2026-10-08T18:07:05.127Z","dateModified":"2026-10-08T18:29:50.653Z","description":"A Russia-aligned threat actor tracked as UAC-0099 has been continuously upgrading its MatchBoil malware downloader since 2024, according to ESET research, to...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/3cbfb00ce6a39cdc61dc67c55694e327?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/3cbfb00ce6a39cdc61dc67c55694e327?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Dark Reading","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Dark Reading","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/dr","url":"https://daily.dev/sources/dr"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/russian-spies-give-matchboil-malware-a-stealthy-facelift-nu7j4gk9z","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":1},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"malware","timeRequired":"PT4M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Dark Reading","item":"https://daily.dev/sources/dr"},{"@type":"ListItem","position":3,"name":"Russian Spies Give 'MatchBoil' Malware a Stealthy Facelift"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/russian-spies-give-matchboil-malware-a-stealthy-facelift-nu7j4gk9z#faq","mainEntity":[{"@type":"Question","name":"What is MatchBoil malware and who is behind it?","acceptedAnswer":{"@type":"Answer","text":"MatchBoil is a malware downloader used by the threat actor UAC-0099, a group believed with moderate confidence to be linked to Russian interests. It delivers a C# backdoor called MatchWok that gives attackers persistent access to compromised systems. The group targets Ukrainian transportation, manufacturing, and energy organizations and is believed to act as an initial access broker for Sandworm. Security teams tracking Russia-linked threat actors can follow malware campaign developments like MatchBoil on daily.dev."}},{"@type":"Question","name":"How has UAC-0099's MatchBoil downloader evolved to evade detection?","acceptedAnswer":{"@type":"Answer","text":"MatchBoil shifted from basic Unicode-based obfuscation in 2024 to commercial Eziriz .NET Reactor obfuscation by 2026, alongside added sandbox checks and a less conspicuous interface. Its persistence mechanism also changed repeatedly, moving from registry values and scheduled tasks to the Windows Run key, then back to scheduled tasks. By late 2025 it began executing every two minutes to repeatedly fetch updated payloads from its command-and-control server. Defenders hardening against evasive droppers can track evolving obfuscation and persistence tactics on daily.dev."}},{"@type":"Question","name":"How do UAC-0099 spear-phishing attacks initially infect victims?","acceptedAnswer":{"@type":"Answer","text":"Attacks typically begin with spear-phishing emails containing a link to an archive file with a VBScript payload. Victims who download and manually execute the script end up with MatchBoil installed. The malware then checks for a specific directory and terminates if it already exists, then gathers machine details used to identify the victim during subsequent command-and-control communications. Incident responders studying phishing-delivered droppers can follow similar threat writeups on daily.dev."}}]}
```

