MatchBoil Malware Explained: How UAC-0099 Uses It to Install the MatchWok Backdoor on Windows

MatchBoil is a small Windows downloader that gets a bigger spying tool onto a victim’s PC. The Russia-aligned group UAC-0099 runs it, and ESET researchers have now mapped two years of its changes. After reading that research, I see the two-minute server check-in as the change that matters most for defenders, because it turns one failed infection attempt into a retry loop.

MatchBoil malware

This guide covers what MatchBoil does, how an infection starts, how it hides, which artifacts to search for on a Windows machine, and which defenses to put in place first.

What Is MatchBoil Malware and What Does It Install?

MatchBoil is a custom C# downloader that pulls a payload from the attacker’s server, installs it, and sets up persistence so it survives a restart.

The payload is MatchWok, a C# backdoor built for espionage. It can capture screenshots of the victim’s desktop and run PowerShell commands, which gives the operator both eyes and hands on the machine. Ukraine’s CERT-UA first documented MatchBoil in August 2025, but compilation timestamps in the samples point to development as early as April 2024. The tool likely ran for about a year before anyone published on it, so older infections may still sit undiscovered.

Who Is UAC-0099 and Which Organizations Does MatchBoil Target?

UAC-0099 operates MatchBoil, and ESET links the group to Russian interests with moderate confidence, mainly because of its targets.

The group has historically gone after government bodies, financial institutions, and media in Ukraine. The MatchBoil campaign widened that list. Telemetry shows these victims:

  • Transportation companies in July and August 2025
  • A manufacturing company in December 2025
  • An energy company in June 2026

ESET also believes UAC-0099 acts as an initial access broker for Sandworm, the group tied to Russian military intelligence and known for destructive attacks on Ukrainian infrastructure. A broker breaks into a network and hands that foothold to another group. The sector shift fits that role. Transport, manufacturing, and energy networks interest other Russian-aligned actors, so a quiet backdoor there has resale value beyond espionage. That is my reading of the pattern, and ESET frames it as a possibility, not a confirmed motive.

How Does MatchBoil Infect a Windows PC?

The attack begins with a spear phishing email that contains a link, not an attachment.

The link downloads an archive that holds a VBScript file. The victim has to extract and run that script by hand, which means the whole chain fails if the user does not double-click. The script downloads and executes MatchBoil. Once running, MatchBoil checks for a specific folder and exits if it already exists, which prevents a double infection.

If the folder is missing, the malware fingerprints the PC using its CPU ID and BIOS serial number. It then sends three HTTPS requests to the attacker’s server. The second response is an HTML page with the payload hidden inside as hex-encoded text. MatchBoil extracts that text, writes the payload to a folder under %LOCALAPPDATA%, and sets it to relaunch through a scheduled task or a registry key.

How Has MatchBoil Evolved Since 2024?

The core job stayed the same, but the operators rebuilt almost everything around it to dodge detection.

ESET compared samples from April 2024 to April 2026 and found these shifts:

  • Execution model: Early versions ran once. By late 2025, MatchBoil ran on a two-minute timer, so a failed first contact with the server no longer ended the infection. It now fetches new or updated payloads on repeat.
  • Obfuscation: The 2024 builds used a homemade, Unicode-based string scrambler. The 2026 builds use Eziriz .NET Reactor, a commercial protector that can virtualize code and tangle control flow.
  • Persistence: The early versions used a registry value plus a scheduled task. Later versions switched to the Windows Run key only. The newest versions went back to scheduled tasks.
  • Interface: Late 2025 builds show a daily planner with a cat photo if a user launches the file manually. The window carries the title “Dairy” and both text boxes read “Today.” The operators toned this down in early 2026.

Of the four changes, the execution model deserves the most attention. Obfuscation and interface tweaks only affect how hard the sample is to analyze. The two-minute loop changes how the infection behaves on the network, and that behavior is the part a defender can still catch when the file itself looks clean.

How Does MatchBoil Evade Sandboxes and Analysis?

MatchBoil reads Windows event logs to decide whether a real person uses the machine.

It looks at system uptime events, searching in both English and Russian. It treats the system as real only if it finds at least three events showing an uptime of 7,200 seconds (two hours) or more. The April 2026 version added a second test that checks whether the operating system was installed at least ten days before the malware runs. Both checks target short-lived analysis environments, so a freshly built test machine may not trigger the malware, and teams that detonate samples should age their test systems first.

MatchBoil Indicators of Compromise: Files, Folders, and Tasks to Check

The payload names changed with each wave, so defenders can search for the whole set of known file and folder names.

ESET and Help Net Security list these indicators:

  • 2024 builds: A payload folder named DeviceMonitor
  • Late 2025 builds: MeowMeowProgramm.exe inside a folder named MeowCheck
  • April 2026 builds: SMTPClientApplication.exe inside a folder named SMTPClient, plus a scheduled task named Checker under a task directory named MailClient

Check %LOCALAPPDATA% for these folders first, then review scheduled tasks and the Run registry key for entries that match. Treat these names as a snapshot, not a permanent signature. The operators renamed the payload at least three times in two years, so a name search will always lag the next version, and behavior-based detection gives better coverage. The attacker also hosts its servers on virtual private server providers such as BitLaunch behind Cloudflare, and its Let’s Encrypt certificates do not repeat across domains, so blocking by hosting provider or certificate will not hold.

How to Protect Against MatchBoil and VBScript Phishing Attacks

The infection depends on a user running a VBScript file from a downloaded archive, so the best controls target that step.

Start with the first two items. They cost the least and stop the chain before any malware runs.

  1. Block or disable Windows Script Host for standard users where the business does not need it, so double-clicking a .vbs file does nothing.
  2. Configure the mail gateway to flag or strip links to archive files that contain script files.
  3. Alert on script interpreters launched from a user’s Downloads or temp folders.
  4. Monitor for new scheduled tasks and Run key entries that point into %LOCALAPPDATA%.
  5. Alert on any process that contacts the same external host about every two minutes, since MatchBoil now beacons on that cycle.
  6. Train staff in transport, manufacturing, and energy teams to treat unexpected emailed archive links as hostile, since those sectors now appear in the target list.

Frequently Asked Questions

What is MatchBoil?

MatchBoil is a C# downloader that UAC-0099 uses to fetch and install the MatchWok backdoor on Windows systems, then keep it running through persistence.

What does the MatchWok backdoor do?

MatchWok is a C# espionage backdoor. ESET says it can take screenshots of the victim’s desktop and execute PowerShell commands on the infected computer.

Who does UAC-0099 target?

All victims in ESET telemetry were in Ukraine, spanning transportation, manufacturing, and energy. The group previously went after government, financial, and media organizations.

How does MatchBoil get onto a PC?

A spear phishing email links to an archive with a VBScript file. The victim must download the archive and run the script, which then downloads MatchBoil.

How does MatchBoil stay on the system?

It writes the payload into a folder under %LOCALAPPDATA% and relaunches it through a scheduled task or a registry key. Recent versions use a scheduled task named Checker.

Why does MatchBoil run every two minutes?

Since late 2025, the loop lets it contact its server repeatedly, so a failed first connection does not stop the infection and the operators can push updated payloads.

Related Guides

Leave a Comment

Comments

No comments yet. Why don’t you start the discussion?

    Leave a Reply