ESET Details MATCHBOIL Malware’s Evolution in Ukraine
ESET says the UAC0099 group has continued refining MATCHBOIL, a downloader used in cyberattacks on organizations in Ukraine, with later versions adding stronger code obfuscation, checks for analysis environments and repeated contact with command-and-control servers. The research describes infections across transportation, manufacturing and energy, but does not establish the campaign’s overall scale. ESET’s observations place infections at transportation companies in July and August 2025, a manufacturing company in December 2025 and an energy company in June 2026. The company said all MATCHBOIL infections it had observed were in Ukraine. Those cases document activity across several sectors; they do not show how many organizations or individuals were compromised overall. The analysis examined MATCHBOIL samples from April 2024 to April 2026. CERT-UA first publicly documented the malware in August 2025, while ESET’s examination of earlier samples suggests development began in 2024. MATCHBOIL is typically delivered through a phishing link to an archive containing a VBScript. A user must run the script for it to download and launch the malware, according to ESET.