ESET traces MATCHBOIL malware changes targeting Ukrainian industry

ESET traces MATCHBOIL malware changes targeting Ukrainian industry

ESET researchers have traced MATCHBOIL malware changes affecting Ukrainian industries. The downloader appeared at transport, manufacturing and energy organisations, while later variants changed how they communicated, persisted and resisted analysis. The findings do not establish attacks on industrial controllers.


ESET researchers have traced changes to a malware downloader used against organisations in Ukraine’s transport, manufacturing and energy sectors, documenting how its operators revised execution, concealment and persistence methods over two years. The MATCHBOIL family has been associated with UAC-0099, a suspected Russia aligned cyberespionage group, although the available findings concern compromised Windows computers rather than proven attacks on industrial control equipment.

The observed activity spans transport companies in July and August 2025, a manufacturing business in December 2025 and an energy organisation in June 2026. ESET also examined malware samples developed between April 2024 and April 2026, allowing its researchers to trace changes that predate some of those detections. The available telemetry identifies the affected sectors without establishing the full extent of access obtained at individual organisations.

In the infection path described by ESET, a targeted email directs a recipient to an archive containing VBScript, which can retrieve and execute the C# downloader MATCHBOIL when run. The downloader then communicates with infrastructure operated by the attackers to obtain configuration information and further malicious software. Each stage provides an opportunity for the operators to change what is delivered after a computer has first been compromised.

By keeping the initial script, downloader and final payload separate, the operators can change the software delivered after a computer has been infected. ESET commonly observed MATCHBOIL installing MATCHWOK, a C# backdoor associated with the same group. Once active, that backdoor may allow commands to be executed or data to be collected, depending on the installed version and the privileges of the affected Windows account.

After execution, MATCHBOIL collects identifying information from the compromised computer, including processor and BIOS characteristics, and sends it to its command infrastructure. The server can use those details to distinguish infections before returning an encoded payload and associated settings. Locally stored configuration and executable material then enable the next stage of the intrusion, subject to the conditions established by the malware and its operating environment.

ESET found that some variants concealed executable content in responses formatted to resemble ordinary HTML, with the downloader extracting encoded data and converting it into a program. This method changes what a basic inspection of the network response may reveal, particularly when analysts are looking for recognisable executable files. Investigators nevertheless need to examine the wider connection and process activity, since encoded material can also appear in legitimate communications.

While early MATCHBOIL versions used encrypted strings and unusual Unicode characters to obscure their code, later samples incorporated the commercial .NET Reactor obfuscation product. These techniques conceal program structure and readable information during static inspection, forcing analysts to work harder to establish which functions will execute. They do not eliminate the need for those functions to run on the compromised computer.

The operators subsequently altered the downloader’s network traffic, moving beyond a single download attempt to repeated requests to the command server. Those additional connections could permit a failed attempt to be repeated or a different payload to be delivered later. Their persistence depends on whether the malware process continues running or a Windows task relaunches it.

To maintain access after a restart, MATCHBOIL variants used scheduled tasks and Windows registry entries that launched supporting scripts or other components. The file names and processes differed between samples, complicating a search based only on one previously identified indicator. Because the same Windows facilities are used legitimately by administrators, investigators must compare unexpected entries with authorised software and the circumstances in which they appeared.

Some later variants also assessed the environment before continuing, checking system uptime, the age of the Windows installation and possible signs of debugging or virtualised analysis. Researchers frequently run suspicious files in temporary virtual machines, and the checks may alter the malware’s behaviour under those conditions. They can also produce ambiguous results on ordinary computers, so their presence gives an indication of attempted evasion rather than a dependable means of identifying every research environment.

In another variation, the malware displayed a seemingly normal daily planner or text search interface when launched directly. Its downloader functions could depend on a different execution route, making the visible application a poor guide to the code’s purpose. Combined with the evolving startup mechanisms and network traffic, such decoys increase the amount of behaviour analysts have to reproduce before they can account for a sample’s capabilities.

The attacks documented by ESET entered through general purpose Windows computers of the kind used for engineering files, maintenance coordination, procurement and production planning. An intrusion into those systems can expose data or credentials relevant to industrial operations, depending on the accounts, files and network connections available. Establishing the consequences requires examining the compromised computer and the access it actually possessed, rather than inferring them from the employer’s sector.

Where operational technology networks are separated from office and engineering computers, additional connections and permissions would be needed to reach programmable logic controllers or safety equipment. ESET has not established that MATCHBOIL directly changed industrial controller operations or caused a manufacturing outage. The observed intrusions therefore support an account of compromise on Windows systems, while any further access into production environments remains unconfirmed.

ESET associates UAC-0099 with Russian interests but qualifies the attribution and possible links to other groups. It has also considered whether the group might provide initial access for Sandworm, an assessment that falls short of identifying Sandworm as a participant in the incidents described. The technical record of downloader behaviour is firmer than the available conclusions about the organisation or organisations directing the activity.

Investigators examining affected Windows systems can look for unusual script execution, new scheduled tasks, unexpected installed files and external connections that coincide with the activity described. Each indicator requires examination against legitimate administration and software deployment before it can be judged malicious. The successive MATCHBOIL variants show continuing development of the attack tooling, although the downstream effects at the observed transport, manufacturing and energy organisations have not been fully established.


Stories for you


  • Magna approves restart of Ontario copper and nickel mine

    Magna approves restart of Ontario copper and nickel mine

    Magna Mining has approved restarting Ontario’s historic Levack copper-nickel mine. A preliminary economic assessment forecasts commercial production in mid-2028, but the company is proceeding without mineral reserves established through a feasibility study.


  • Nucor proposes 5m expansion of Indiana pole manufacturing

    Nucor proposes $105m expansion of Indiana pole manufacturing

    Nucor plans new capacity for steel utility structures in Indiana. The proposed $105 million Crawfordsville expansion adds more than 120,000 square feet of manufacturing space and is expected to create 100 jobs, subject to approvals.