Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-10-09 · updated: 2026-10-09 · tags: [incident, defence] · confidence: high · severity: low · affected_sectors: [defence] · au_impact: true

ESET published research on 8 October documenting the MATCHBOIL downloader used by UAC-0099, a group it assesses with medium confidence to be aligned with Russian interests, across versions compiled or observed between April 2024 and April 2026 — each more evasive than the last. MATCHBOIL is a C# downloader that retrieves, installs and persists additional payloads; earlier versions relied on unprintable Unicode characters and string encryption, but by late 2025 the operators had adopted the Eziriz .NET Reactor obfuscator and added sandbox checks, and moved from one-shot execution to a two-minute timer that pulls a newer payload from command-and-control. Persistence shifted between a Run key plus scheduled task, Run-key-only and back to scheduled tasks, and later samples shipped a decoy daily-planner interface — dropped by a February 2026 sample in favour of a regex text-search utility. ESET observed MATCHBOIL victims in Ukraine across transportation, manufacturing and energy, with activity as recently as June 2026; CERT-UA first documented the malware in August 2025, but ESET found samples suggesting development began as early as April 2024. The pattern — a downloader treated as a maintained product rather than a fixed tool — is the practical signal for detection teams.

Attribute Detail
Sector Defence
Date 2026-10-09
Source ESET (WeLiveSecurity)
Reliability Tier 1