Fraud Management & Cybercrime,
Next-Generation Technologies & Secure Development,
Ransomware
Malware Has Hit Ukrainian Transport, Energy and Manufacturing Firms

A recent investigation into cybercriminal activities has revealed that a cyberespionage group connected to Russian military intelligence has been intensively refining a specialized downloader, known as Matchboil, which is being utilized against various Ukrainian organizations. Since its initial documentation by Ukrainian incident responders in 2025, the downloader has shown considerable evolution and sophistication, having been in development as early as April 2024, according to cybersecurity experts from the firm Eset. This relentless improvement of Matchboil suggests that it plays a pivotal role in the cyber operations aligned with Russian interests.
The malware’s constant upgrades point to its integral function within the hacking operations associated with the UAC-0099 group, which has been under constant surveillance by Ukrainian cyber defenders since 2022. Eset has expressed a medium level of confidence in the malware’s alignment with Russian operational objectives, suggesting its capacity to serve as an initial access broker for a more notorious Russian hacking faction referred to as Sandworm, which is formally designated as Unit 74455 of the Russian Main Intelligence Directorate.
“The evolutionary trajectory of Matchboil has seen it transition from a one-time downloader to a downloader capable of communicating with command-and-control (C&C) servers every two minutes,” stated Eset researcher Fernando Tavella. “In late 2025, UAC-0099 augmented the downloader with a graphical user interface (GUI) that activates upon the execution of the payload. However, in early 2026, the group opted for a less-obtrusive version.” This adaptability allows the malware to blend in more effectively and evade detection.
Matchboil has reportedly impacted a myriad of sectors in Ukraine, affecting multiple transportation firms, manufacturing industries, and energy companies. The widespread implications of this malware showcase a troubling trend of cyberattacks that can disrupt essential services and infrastructure.
The investigation into Matchboil by Eset began in February after researchers observed two sample instances uploaded to VirusTotal, which were found to be communicating with a domain previously linked to UAC-0099. This initial finding led to the discovery of additional variants that dated back to earlier years. The attackers employed sophisticated methods, primarily through spear phishing emails, to distribute the malware. Clicking on malicious links would result in the downloading of an archive file containing a VBScript payload, which would subsequently execute Matchboil on the victim’s machine.
Once the malware is deployed on a system, it captures critical identifiers from the victim machine, which may include CPU information and the motherboard’s serial number stored in the firmware. This data is crucial for maintaining ongoing communication with the command-and-control servers. Additionally, subsequent iterations of Matchboil began collecting even more detailed information, such as username, MAC address, model, and manufacturer of the computer.
The communication with the C&C server ultimately sets the stage for the installation of a C# backdoor recognized as Matchwok, which has been exclusively attributed to UAC-0099, along with various configuration instructions essential for its function. “After concluding communication with the C&C server, Matchboil ensures the persistence of the installed payload, a PE file, for future execution,” Eset declared. “The persistence mechanism can be established through scheduled tasks or by modifying Windows registry settings.”
By the end of 2025, Matchboil had significantly advanced from a basic downloader to a more complex malware system that would initiate operations every two minutes to download the most recent payload from its C&C server, which was cleverly disguised using private virtual servers like BitLaunch and cloud service providers like Cloudflare. The technical enhancements included shifting away from unprintable Unicode characters and simple encryption methods to utilizing the Eziriz .NET Reactor obfuscator. This commercial tool offers advanced code virtualization and control flow obfuscation capabilities, complicating any malware analysis efforts.
The persistence methods employed by Matchboil also underwent transformations over the years. Initially relying on a registry entry and scheduled tasks in 2024, by July 2025, it shifted to a more minimalist approach, exploiting the Windows Run registry key, thereby ensuring its activation upon user login. By late 2025, the malware’s persistence strategy became more flexible, allowing operators to execute the malware at predetermined intervals.
In its later iterations, enhancements made to Matchboil also included defensive evasion techniques. The updates allowed the malware to check whether it was operating in a controlled, sandbox environment, further complicating detection efforts by cybersecurity measures. A deceptive graphical user interface, mimicking a benign daily planner with an inconspicuous background of a surprised-looking ginger cat, was introduced to obscure the more malicious behaviors of the malware if a user tried to manually execute the payload.
Most recently, in 2026, this fake user interface was replaced with a more subtle utility designed for searching text files. In a notable innovation for 2026, the latest variant of Matchboil transitioned from being an executable (EXE) to a dynamic-link library (DLL) file, executed through a custom C# loader. It further incorporated a logic to terminate itself if the operating system had been installed less than 10 days prior to its execution, along with a range of other enhancements aimed at improving stealth and operational efficiency.