Close Menu
NCIJ Network NCIJ Network
    What's Hot

    American Ignorance Risks Fueling Deadly Middle East Sectarianism

    October 8, 2026

    Did Chuck Schumer say ‘our ultimate goal’ is to give citizenship to immigrants already in US?

    October 8, 2026

    Adidas sues Australian label White Fox over four stripes design

    October 8, 2026
    Facebook X (Twitter) Instagram
    Trending
    • American Ignorance Risks Fueling Deadly Middle East Sectarianism
    • Did Chuck Schumer say ‘our ultimate goal’ is to give citizenship to immigrants already in US?
    • Adidas sues Australian label White Fox over four stripes design
    • Russian strike on buses kills at least 30, say officials, as deadly attacks on Ukraine surge
    • Campaigners led by Chris Packham urge prime minister to rethink Send overhaul | Special educational needs
    • White House blocks Microsoft from foreign worker hiring program
    • JetBrains Releases Mellum2.1: A 12B MoE Open Model for Coding Agents
    • FBI Says China-Linked Hackers Ran Portal Giving Third Parties Access to Stolen Emails
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Thursday, October 8
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Russian Spies Give ‘MatchBoil’ Malware a Stealthy Facelift

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKOctober 8, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A likely Russia-affiliated cyber-espionage group is using an increasingly sophisticated malware downloader to target Ukrainian organizations across the transportation, manufacturing, and energy sectors.

    According to ESET, the group, tracked as UAC-0099, is using the downloader, dubbed MatchBoil, to deliver MatchWok, a C# backdoor that gives the attacker persistent access to compromised systems.

    The security vendor’s analysis showed that MatchBoil has been in active development since at least 2024, and has kept steadily improving with every iteration since then. Though its core function remains the same — to download additional payloads — the latest edition of the malware features stronger obfuscation, sandbox checks, and evolving persistence mechanisms, researchers warn.

    A Constantly Evolving Malware Strain

    Overall, MatchBoil has evolved from what ESET terms a “one-shot downloader” into a dropper capable of repeatedly retrieving updated payloads from its command-and-control (C2) server.

    Related:OpenAI Agent Escape Causes Wikimedia Service Outage

    “Our investigation of MatchBoil samples from April 2024 to April 2026 revealed multiple modifications, from code-level structure to the use of the .NET Reactor obfuscator, all of these implemented in a relatively short time,” ESET said in a technical report this week. “This demonstrates a keen interest by UAC-0099 operators in improving their downloader, not only to avoid detection by security solutions, but also to use it as a key part of their toolset in future attacks.”

    Russia-Aligned Cyber Espionage?

    UAC-0099 is a threat actor operating since 2023, which ESET believes with moderate confidence is linked to Russian interests, primarily because it targets Ukrainian organizations. The security vendor also thinks it’s likely that UAC-0099 is an initial access broker for Sandworm, the threat actor linked to Russia’s military intelligence agency and responsible for numerous destructive attacks on Ukraine’s power grid and other infrastructure. In the MatchBoil campaign, UAC-0099 initially targeted transportation companies before expanding its focus to manufacturing and, more recently, the energy sector.

    The threat actor’s attacks typically have begun with spear-phishing emails containing a link to an archive file with a VBScript payload. Users tricked into downloading and manually executing the script end up with MatchBoil on their systems. Once running, the malware checks for the presence of a specific directory on the victim’s machine and terminates if the directory already exists, according to ESET. The malware then obtains specific details about the machine, which it uses to identify the victim during subsequent C2 communications.

    Related:ClickFix Attacks Evolve to Better Hide Malicious Payloads

    MatchBoil: New & Improved Malware Capabilities

    Samples of the malware that ESET examined showed UAC-0099 steadily refining MatchBoil to make it harder for defenders to detect and analyze. While the 2024 versions, for instance, relied on relatively basic Unicode-based obfuscation, the 2026 edition uses Eziriz .NET Reactor, a commercial .NET obfuscation and protection tool for making an application’s code harder to reverse engineer and analyze. Similarly, newer versions of the malware include sandbox checks and a less conspicuous interface designed to avoid detection by security researchers and users.

    UAC-0099 has also been constantly tinkering with MatchBoil’s persistence mechanisms, too, ESET noted. Initial versions of the malware used both a registry value and a scheduled task to maintain persistence on compromised systems and ensure the payload would continue to run on them, even through system reboots. Later versions switched to the Windows Run key exclusively to launch the malware when a user logged in to the system. Last year, the malware authors went back to using scheduled tasks as a persistence mechanism.

    Related:Chinese Hackers Impersonate US Officials for AI Cyber Espionage

    ESET found that by late 2025, MatchBoil had evolved from a dropper that essentially ran once, contacted its C2 server, and downloaded and installed a next-stage payload, into one that executed every two minutes. The change allowed it to repeatedly contact its control server and retrieve new or updated payloads.

    “From all the samples of the downloader that we collected, we see that UAC‑0099 is continually improving MatchBoil for future attacks,” ESET concluded. “The samples compiled or seen before November 2025 were much more straightforward and simple to analyze compared to newer ones.”

    Facelift Give Malware MatchBoil Russian Spies Stealthy
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Did Chuck Schumer say ‘our ultimate goal’ is to give citizenship to immigrants already in US?

    Russian strike on buses kills at least 30, say officials, as deadly attacks on Ukraine surge

    FBI Says China-Linked Hackers Ran Portal Giving Third Parties Access to Stolen Emails

    Cisco Patches a Dozen Critical Vulnerabilities

    AWS’s repeated problems with AI agent controls illustrates the autonomous agent dilemma

    Cisco warns of critical flaws allowing Nexus switch takeover

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    American Ignorance Risks Fueling Deadly Middle East Sectarianism

    October 8, 2026

    Did Chuck Schumer say ‘our ultimate goal’ is to give citizenship to immigrants already in US?

    October 8, 2026

    Adidas sues Australian label White Fox over four stripes design

    October 8, 2026

    Russian strike on buses kills at least 30, say officials, as deadly attacks on Ukraine surge

    October 8, 2026
    Latest Posts

    Wisconsin’s partisan primary election is Tuesday. Learn more about who’s on your ballot.

    August 10, 2026

    Gabon ends fisheries partnership agreement with EU

    August 10, 2026

    Science backs calls for limiting screens in schools

    August 10, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    American Ignorance Risks Fueling Deadly Middle East Sectarianism

    October 8, 2026

    Did Chuck Schumer say ‘our ultimate goal’ is to give citizenship to immigrants already in US?

    October 8, 2026

    Adidas sues Australian label White Fox over four stripes design

    October 8, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.