MATCHBOIL is a C#-based downloader tool attributed to the UAC-0099 group, now actively deploying backdoor malware using command-and-control (C2) servers masked behind Cloudflare protections. While it once functioned as a straightforward downloader, the malware now includes expanded evasion tactics, frequent server communication, more complex payloads, and built-in countermeasures to thwart analysis. The campaign has been observed across various industrial sectors in Ukraine, with activity recorded from mid-2025 through mid-2026.
Infection Chain and Deployment Methods
Attacks begin with phishing emails that trick recipients into extracting an archive containing a VBScript. The recipient must manually execute this script, which then downloads and runs the MATCHBOIL malware. Earlier campaigns by this threat actor leveraged fake court notices and other document-based lures to spread HTA files. Once launched, MATCHBOIL checks if its install location already exists; if so, it may stop to avoid redundancy, reducing detection risk.
The downloader gathers detailed system data via Windows Management Instrumentation (WMI) such as processor IDs and BIOS serial numbers. Newer variants also capture information about network environment and machine configuration. MATCHBOIL reaches out to its hidden C2 infrastructure through a series of three HTTPS requests: the first picks up a number used in the second request’s header, the second returns a hex-encoded payload embedded in HTML (which is decoded and written to disk), and the third probably delivers configuration data. The backdoor software often installed by MATCHBOIL has been identified as MATCHWOK.
Hardening, Evasion & Infrastructure Shifts
To help hide its operations, the group uses virtual private servers, including BitLaunch, and Cloudflare for hiding the true location of its C2 servers. TLS certificates are issued via Let’s Encrypt, avoiding reuse across domains. More recent MATCHBOIL builds abandon earlier obfuscation like Unicode-based hiding and custom string encryption, replacing them with .NET Reactor protection. The malware also implements checks for debugger presence and examines system uptime via Windows event logs to evade analysis environments.
Earlier versions contacted C2 only once, but newer variants reach out every two minutes, allowing for retries in case downloads fail and enabling delivery of updates. Some samples show embedded decoy GUIs—fake planner or text-search windows—that run when expected arguments are missing. An April 2026 variant, called MATCHBOIL.V2, runs as a DLL through a custom loader, installs executables in user-local directories mimicking legitimate software, and uses scheduled tasks themed around email or SMTP functionality rather than the more obvious animal-themed names used previously.
Geography, Targets & Indicators of Compromise
Recorded victims are all in Ukraine. Transportation companies were hit in July and August 2025; a manufacturing firm in December 2025; and an energy company in June 2026. These incidents show breadth across sectors, though the full scope of infections remains unclear. The group is assessed to have started moving development earlier than its first public mention in August 2025. Intelligence agencies judge UAC-0099’s alignment with Russian interests as medium confidence.
Security teams should monitor for specific indicators, including suspicious scheduled tasks, unexpected VBScript execution, C# programs making repeated HTTPS requests, and file-paths or names matching sample payloads like “AnimalUpdater.exe” or “PlannerAssistantManager.exe”. Further IoCs include filenames, SHA-1 hashes, domain names (e.g. virtualdailyplanner[.]pro, telemetry-conf[.]com), and established registry or persistence mechanisms. Behavioral detection—looking at what an executable does—has become more critical than relying solely on filenames or network traffic flagged by domain alone, especially given Cloudflare usage.
What this signifies is how malware operations are growing more sophisticated. MATCHBOIL’s shift from a one-off downloader to a persistent, stealthy backdoor with real-time C2 communication reflects broader trends in threat actor capability. For defenders, the challenge is raising visibility into behavior (not just files or alerts), effectively monitoring scheduled tasks, system uptime logs, and unusual HTTPS patterns. Going forward, tracking how UAC-0099 expands its targeting or changes infrastructure—especially new domain reuse or certificate practices—will be crucial.