Russia aligned group upgrades MATCHBOIL malware used against Ukrainian targets
Researchers have documented two years of upgrades to the MATCHBOIL downloader, which a Russia-aligned group is using to target organizations in Ukraine.
FTMQ Security, written by our newsroom0 views

The Russia-aligned cyber espionage group UAC-0099 has steadily upgraded its MATCHBOIL downloader to target organizations in Ukraine, according to research published by ESET on October 8. InfoSecurity Magazine and Help Net Security both reported that ESET tracked changes to the malware compiled or observed between April 2024 and April 2026. Dark Reading and The Manila Times also reported that the group has refined the tool during its campaigns. [1][2][3][4]
ESET researchers found that each new version of MATCHBOIL added stronger obfuscation, sandbox checks, and modifications to execution and payload persistence. Help Net Security reported that UAC-0099 uses the downloader to plant a second program on Windows machines. The upgrades have made the malware increasingly difficult for security analysts to examine. [1][2]
According to Help Net Security, all victims in ESET telemetry were located in Ukraine. The group targeted transportation companies in July and August 2025, a manufacturer in December 2025, and an energy firm in June 2026. InfoSecurity Magazine noted that UAC-0099 has additionally targeted Ukrainian government organizations, financial institutions, and media entities. [1][2]
InfoSecurity Magazine reported that ESET assesses with medium confidence that UAC-0099 aligns with Russian interests. The continued evolution of MATCHBOIL shows that the group is actively maintaining its cyber espionage tools to sustain access to critical Ukrainian infrastructure and computer networks. [1][2][3][4]
In short
- ESET documented MATCHBOIL malware versions compiled or observed between April 2024 and April 2026.
- The MATCHBOIL downloader is used by the Russia-aligned group UAC-0099 to target Windows systems in Ukraine.
- Targeted sectors in Ukraine include transportation, manufacturing, energy, government, finance, and media.
Sources
Every paragraph above points to the numbered items it rests on. Read the originals here.
- [1]Russia-Aligned UAC-0099 Evolves MATCHBOIL MalwareInfoSecurity Magazine, 12h ago (the report this story comes from)
- [2]What is MATCHBOIL? The Russia-aligned malware that installs a spying backdoorHelp Net Security, 16h ago
- [3]Russian Spies Give 'MatchBoil' Malware a Stealthy FaceliftDark Reading, 7h ago
- [4]Russian-aligned UAC-0099 intensifies attacks on Ukrainian industry with evolving MATCHBOIL downloaderThe Manila Times, 15h ago
Our newsroom writes these reports with the help of software, from the 4 sources listed and nothing else, and checks them against those sources. Facts can still be wrong or move on; the originals are the record. Spotted a mistake? Write to daniel@monsterkong.com.
More in Data Breaches
- Coupang files lawsuits over 620 billion won data leak fine1h ago
- ASOS confirms data breach following social engineering attack on employee credentials1h ago
- OT Coalition Urges CISA to Mandate Security Standards for Federal Systems1d ago
- Hackers hide VBScript payloads in browser caches via fake CAPTCHAs2d ago
- New Linux Backdoors Target Telecom Appliances in South Korea and Taiwan3d ago
- ClingSTUN Linux Backdoor Turns Unpatched IoT Devices Into Proxy Nodes3d ago
Get the day in one email
Reports like this one, the top news of the last 24 hours, every morning. Free, one email a day; readers can comment under every report.
By signing up you agree to our terms and privacy policy. Unsubscribe any time.

Comments
Loading
Join the conversation
Comments are open to readers of our daily email: the top news of the last 24 hours, every morning, free. Sign up and the comment box opens.
Already on the list? Enter the same address and we will send a sign-in link.
By signing up you agree to our terms and privacy policy. Unsubscribe any time.