That assessment comes with a recent and detailed timeline. In research published on October 8, ESET traced steady upgrades to a C# downloader named MATCHBOIL between samples compiled or observed from April 2024 through April 2026. The changes are deliberate, cumulative and aimed at making the tool harder to analyze and more flexible in delivery—characteristics the researchers say reflect a group they call UAC-0099, which ESET assesses with medium confidence to be aligned with Russian interests.
ESET's findings on MATCHBOIL's evolution
ESET documented multiple MATCHBOIL versions and found a clear pattern of incremental sophistication. Although Ukraine's Computer Emergency Response Team (CERT-UA) first documented MATCHBOIL in August 2025, ESET located earlier samples that suggest development may have begun as early as April 2024. Across the two-year window, the downloader's role remained consistent: retrieve, install and establish persistence for additional payloads. What changed was how MATCHBOIL performed those tasks—its obfuscation, sandbox evasion, execution timing and persistence techniques all shifted as new samples appeared.
Obfuscation and sandbox checks introduced late in 2025
The earliest MATCHBOIL variants relied on relatively simple anti-analysis measures: unprintable Unicode characters and string encryption that make static inspection harder. By late 2025 the operators had adopted the Eziriz .NET Reactor obfuscator, a commercial tool capable of code virtualization and control-flow obfuscation. Around the same time, ESET observed the gradual introduction of sandbox-detection checks. These runtime checks, added stepwise from late 2025, were designed to identify automated or emulated analysis environments and frustrate researchers and automated scanning systems.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildExecution model and persistence shifted across samples
MATCHBOIL's runtime behavior also changed. Early samples functioned as one-shot downloaders—run once to fetch and install a payload. A late-2025 variant adopted a two-minute timer, periodically polling its command-and-control (C2) server to retrieve newer payloads. Persistence mechanisms evolved in parallel: 2024 samples combined a Windows Registry Run key value with a scheduled task; a July 2025 sample relied on Run key entries alone; later samples reverted to using scheduled tasks. These changes show an operational willingness to adjust techniques for staying resident on infected hosts.
User-facing disguises: planner GUI then a text-search utility
UAC-0099's operators experimented with GUIs intended to conceal MATCHBOIL when it was launched manually. Late-2025 samples displayed a daily-planner-style graphical interface, although ESET noted several inconsistencies that weakened the disguise. By February 2026, a sample presented a lower-profile utility for searching text files using regular expressions—an interface with less obvious flaws and more plausible functionality, according to the researchers. Taken together, these interfaces suggest the operators were testing both overt and subtle decoys to blend malicious activity with benign user actions.
UAC-0099 targeting and observed victims in Ukraine
ESET linked MATCHBOIL to a group it calls UAC-0099, which the company said has targeted Ukrainian government organizations, financial institutions and media. The researchers reported MATCHBOIL victims in Ukraine across transportation, manufacturing and energy sectors, with activity observed as recently as June 2026. That geographic and sectoral footprint, combined with the tool's evolution, led ESET to characterize MATCHBOIL as an actively maintained component of the group's toolkit rather than a one-off downloader.
What this means for technologists, policymakers, and Ukrainian enterprises
- Technologists and security teams should expect an evolving downloader: MATCHBOIL demonstrates that small, frequent changes—to obfuscation, sandbox checks, timers and persistence—can materially increase analysis difficulty and detection evasion. Teams will want layered detection that accounts for behavior over static signatures.
- Policymakers and incident-response coordinators tracking state-aligned cyber activity can use the timeline—April 2024 to April 2026, with victim activity through June 2026—to prioritize information sharing and to ensure CERTs and ISACs receive samples quickly when new variants emerge.
- Ukrainian enterprises in transportation, manufacturing and energy should note that MATCHBOIL has been observed in their sectors and that operators are iterating runtime and disguise techniques; defenders in those sectors will need to watch for both registry and scheduled-task persistence and atypical periodic network retrievals from endpoints.
MATCHBOIL's arc—early obfuscation and encryption, a shift to commercial obfuscation, the staged introduction of sandbox checks, and alternating persistence methods—reads as deliberate engineering. ESET's finding that the group treats the downloader as an evolving toolkit component is supported by the sequence of changes and the breadth of observed victims. Activity recorded as recently as June 2026 raises a concrete question the record leaves open: will UAC-0099 continue to iterate MATCHBOIL beyond April 2026, and if so, which defensive gaps will the next variant target?
Original reporting: https://www.infosecurity-magazine.com/news/russia-aligned-uac-0099-evolves/




