Secure Bulletin Navigating the cyber sea with knowledge
Home > Articolo > UAC-0099 Refines MATCHBOIL Malware With Cloudflare-Hidden Servers to Hit Ukrainian Organizations
UAC-0099 Refines MATCHBOIL Malware With Cloudflare-Hidden Servers to Hit Ukrainian Organizations
Read Time:3 Minute, 52 Second

A threat group tracked as UAC-0099, assessed with medium confidence by ESET to align with Russian interests, has spent the past two years steadily upgrading a C# malware downloader called MATCHBOIL. New research from ESET’s WeLiveSecurity team shows the tool evolving from a straightforward downloader into a more resilient piece of infrastructure, now hiding its command-and-control servers behind Cloudflare and adding checks designed specifically to frustrate researchers.

A Year of Confirmed Victims in Ukraine

ESET’s review covered malware samples dating from April 2024 through April 2026, and every observed victim was located in Ukraine. Recorded infections hit transportation companies during July and August of last year, a manufacturing company in December, and an energy-sector organization as recently as June 2026. While these findings confirm sustained targeting across multiple sectors, ESET is careful to note they don’t establish the campaign’s full scale — there are likely infections that haven’t surfaced in this dataset.

Ukraine’s CERT-UA first documented MATCHBOIL publicly in August 2025, though build timestamps examined by ESET suggest development began well before that disclosure.

Phishing Emails and a Manual Step

The infection chain starts with targeted phishing emails carrying a malicious attachment. Victims download an archive containing a VBScript file and, critically, have to manually run that script themselves before MATCHBOIL downloads and launches. This mirrors earlier UAC-0099 campaigns that relied on fake court notices and other document-themed lures to get targets to open the initial file.

Once running, MATCHBOIL first checks whether its installation directory already exists, allowing it to avoid re-infecting a machine it has already compromised. It then gathers device fingerprinting data through Windows Management Instrumentation, including processor identifiers and BIOS serial numbers; newer versions also collect network address information to help operators distinguish between victim machines during later contact.

A Three-Step Handshake With the Command Server

MATCHBOIL’s communication with its command infrastructure follows a specific three-request pattern. The first request returns a number that gets included in a header on the second request — researchers believe this may help select a particular payload or validate the request, though its exact purpose isn’t fully confirmed. The second response delivers HTML containing a payload hidden as hexadecimal text, which MATCHBOIL extracts with a regular expression, converts to binary, and writes to disk. In most observed cases, that payload turned out to be MATCHWOK, a separate C# backdoor also attributed to UAC-0099. A third and final request retrieves what appears to be configuration data for the deployed backdoor.

Hiding Behind Cloudflare and Slowing Down Analysts

UAC-0099 hosts its infrastructure on virtual private servers, including some running through BitLaunch, and increasingly routes traffic behind Cloudflare to mask the true location of its command servers — a technique ESET notes echoes similar cloud-proxy abuse seen from other groups, including MuddyWater. The group has also started using Let’s Encrypt certificates that aren’t reused across different domains, making tracking by certificate fingerprint less reliable.

Later versions of the malware layer on Unicode-based code obfuscation and custom string encryption using the Eziriz .NET Reactor tool, alongside debugger checks and a specific uptime verification — examining Windows event logs for evidence of at least two hours of continuous system uptime — all aimed at distinguishing real victim machines from short-lived sandbox and analysis environments.

Once past those checks, MATCHBOIL contacts its command server every two minutes rather than just once, giving operators repeated chances to deliver updated payloads even if an earlier attempt fails. When launched without the arguments it expects, the malware displays fake planner or text-search windows to distract anyone who stumbles onto it directly.

Naming Conventions Keep Shifting Too

An April 2026 variant CERT-UA calls MATCHBOIL.V2 runs as a DLL loaded through a custom C# loader, dropping its payload into a folder named after an SMTP client and creating a mail-themed scheduled task — a deliberate move away from the more conspicuous animal-themed filenames used in earlier builds, suggesting the operators are consciously trying to blend in with legitimate software naming.

  • Watch for unexpected VBScript execution following email attachment downloads.
  • Flag repeated HTTPS connections at roughly two-minute intervals from unfamiliar C# executables.
  • Audit newly created scheduled tasks, particularly those using mail- or planner-themed names.
  • Cross-reference host and network indicators from ESET’s published IoC list rather than relying on file hashes or Cloudflare traffic alone, since both change frequently.

Given the group’s steady investment in evasion and its continued focus on Ukrainian critical infrastructure sectors, defenders in the region should treat MATCHBOIL-style phishing lures as an ongoing, evolving threat rather than a one-time campaign to patch against and forget.

Share: Twitter  |  Facebook  |  LinkedIn
Join the discussion

This is a blog in the Fediverse: you can find this article everywhere with @blog@securebulletin.com and every comment/answer will appear here.

If you want to comment on UAC-0099 Refines MATCHBOIL Malware With Cloudflare-Hidden Servers to Hit Ukrainian Organizations, use the discussion on Forum.

>> forum community

Comments

Leave a Reply