Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

MATCHBOIL is a Windows downloader that ESET attributes to the UAC-0099 cyberespionage group. It retrieves and installs another payload—usually the MATCHWOK backdoor in the samples ESET examined—which can be used for espionage. ESET assesses with medium confidence that UAC-0099 is aligned with Russian interests; that is an attribution assessment, not proof of Russian state direction.

What MATCHBOIL does—and how it differs from MATCHWOK

MATCHBOIL is the first-stage malware in a delivery chain: its role is to fetch, install, and maintain another program on a compromised computer. ESET says the second-stage payload was MATCHWOK in most of the samples it analyzed. MATCHWOK is the backdoor associated with espionage; MATCHBOIL is the downloader that brings it in. The distinction matters because the names refer to different components, not interchangeable labels. ESET’s technical analysis describes the downloader and its payload.

How the documented infection chain works

1. A spear-phishing link delivers an archive

ESET describes delivery through malicious links in spear-phishing emails. The link downloads an archive containing a VBScript file. The infection requires a person to run that script; the documented chain is not simply a case of opening the email. ESET’s analysis details this delivery method.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

2. The script downloads and runs MATCHBOIL

Once executed, the VBScript downloads and launches MATCHBOIL. The delivery script may also create persistence for MATCHBOIL itself, separate from the persistence the downloader establishes for its installed payload.

#1 Best Overall

3. MATCHBOIL checks the machine and contacts its server

MATCHBOIL checks for an installation directory under %LOCALAPPDATA% and exits if that directory already exists. It collects machine identifiers, including the CPUID and BIOS serial number, and then makes three HTTPS requests to its command-and-control (C&C) server.

ESET reports that the second response contains HTML-like content with a hex-encoded payload. MATCHBOIL extracts and decodes that data, then installs the payload. The third response is a string saved alongside the installed file; ESET says it may serve as configuration. These details describe behavior ESET observed in the analyzed samples, not a guarantee that every version uses an identical exchange.

4. Persistence keeps the installed payload available

Depending on the version, MATCHBOIL uses a Windows scheduled task or a registry value to persist the installed executable. The delivery script can separately provide persistence for MATCHBOIL, so defenders may need to consider both the loader and its payload when investigating an affected host.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How MATCHBOIL changed across analyzed versions

ESET analyzed samples compiled or observed between April 2024 and April 2026. Sample timestamps point to possible development as early as April 2024, but timestamps do not establish a confirmed launch date. ESET says MATCHBOIL was first publicly documented by CERT-UA in August 2025. The progression below summarizes changes ESET reported; it should not be read as a feature checklist shared by every sample.

Behavior Earlier samples Later samples ESET analyzed
C&C communication One-shot downloader behavior Attempts communication every two minutes
Obfuscation Unicode symbol renaming and custom string encryption Eziriz .NET Reactor
Persistence Registry Run keys in some versions Scheduled tasks in other versions
Analysis-environment checks and user-facing behavior Not described as present in early samples Late-2025 samples added checks intended to detect analysis environments and displayed a decoy interface when launched manually

Sandbox checks are version-specific

In late-2025 samples, ESET observed a check of Windows Event ID 6013 uptime logs. The malware treated a system as outside a sandbox when it found at least three uptime events showing at least 7,200 seconds (two hours). The April 2026 version also checked whether Windows had been installed at least ten days before execution. These are behaviors of specific analyzed variants, not universal requirements for MATCHBOIL.

What is known about UAC-0099 and its targets

ESET describes UAC-0099 as a cyberespionage group that has targeted Ukrainian government organizations, financial institutions, and media. Based on targeting, ESET Research assesses with medium confidence that the group is aligned with Russian interests. ESET also says UAC-0099 may act as an initial access broker for Sandworm. These are attributed assessments; they do not establish state control or prove who directed a particular intrusion. ESET explains its attribution and confidence level.

ESET telemetry associated with MATCHBOIL samples with Ukrainian organizations in several sectors: transportation companies in July and August 2025, a manufacturing company in December 2025, and an energy company in June 2026. These are observations within ESET’s telemetry, not a complete victim list or an estimate of how widespread infections are. ESET’s report does not provide a population-level victim count or an independently verified infection rate.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Detection and response: what the available guidance supports

Use current indicators for threat hunting

ESET’s article provides example sample names and SHA-1 hashes and links to a repository containing a more comprehensive set of indicators and samples. Because files and infrastructure can change, consult ESET’s MATCHBOIL indicator repository for operational hunting rather than treating a short list of hashes or network details as complete or durable.

ESET reports that UAC-0099 used VPS providers such as BitLaunch and Cloudflare to obscure C&C servers, with HTTP and HTTPS observed. Those infrastructure details can change; a provider name alone is not a reliable blocklist.

Keep vendor-specific detection advice in context

Trend Micro’s DDI Rule 5515 reference identifies Matchboil Downloader HTTP requests and advises customers to update Trend Micro products and scan the host exhibiting the behavior. This is guidance for Trend Micro products, not a comprehensive incident-response procedure for all organizations. If MATCHBOIL activity is suspected, preserve relevant evidence and follow your organization’s security incident-response process; the cited vendor sources do not provide a complete general-purpose cleanup playbook.

Related reporting on another delivery method

An earlier Broadcom/Symantec bulletin reported malicious HTA files used to deliver MatchBoil, with payloads including MATCHWOK and DRAGSTARE. That differs from the spear-phishing link and VBScript chain detailed in ESET’s later analysis. Delivery methods can vary across campaigns and periods, so the VBScript path should not be assumed to cover every reported MatchBoil infection. Broadcom/Symantec’s August 2025 bulletin describes the HTA activity.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.