MATCHBOIL: New tricks, same old evil intentions

https://web-assets.esetstatic.com/wls/2026/10-26/matchboil/matchboil-eset-research.png

ESET researchers have documented the evolution of the MATCHBOIL malware, a custom C# downloader wielded by the Russia-aligned UAC-0099 APT group. The malware is used to download a payload from the group’s C&C server, install it, and establish its persistence. Although MATCHBOIL was first documented by CERT-UA in August 2025, our research indicates that it has been in development since at least 2024. The earliest versions of the malware that we analyzed are from April 2024 and the latest from April 2026. This blogpost goes over these versions chronologically and describes the malware’s changes. Each new iteration of the downloader was more sophisticated than the last, showing that MATCHBOIL is an important part of UAC-0099’s toolkit.

Key points of the blogpost:MATCHBOIL is a C# downloader used by the Russia-aligned group UAC‑0099 to download, install, and persist another payload.The analyzed MATCHBOIL versions show a change in code obfuscation from...

Copyright of this story solely belongs to www.welivesecurity.com. To see the full text click HERE

Read more