Skip to content
Threat Feed
high threat

Evolution of UAC-0099's MATCHBOIL Downloader

UAC-0099, a Russia-aligned threat actor, uses the evolving MATCHBOIL C# downloader to target Ukrainian sectors via spearphishing and secondary payload delivery.

UAC-0099, a Russia-aligned cyberespionage group active since at least 2022, has been systematically evolving the MATCHBOIL downloader since April 2024. MATCHBOIL is a custom C# malware designed to download, install, and persist subsequent payloads, such as the MATCHWOK backdoor. Initially a straightforward one-shot downloader, the malware has matured to include sophisticated obfuscation via the Eziriz .NET Reactor, multi-stage execution on timers, and sandbox evasion techniques. ESET researchers have identified victims across various Ukrainian sectors, including transportation, manufacturing, and energy. The actor frequently acts as an initial access broker for other groups, including Sandworm. Defenders should monitor for suspicious C# binaries, unusual VBScript execution, and irregular HTTPS traffic patterns associated with identified C2 domains.

Attack Chain

  1. The attacker sends spearphishing emails containing links to an archive file.
  2. The victim downloads and manually executes a VBScript payload contained within the archive.
  3. The VBScript downloads and executes the MATCHBOIL downloader binary.
  4. MATCHBOIL performs environment checks, including WMI queries and sandbox detection, to verify the execution environment.
  5. MATCHBOIL initiates an HTTPS connection to the C2 server to retrieve a command identifier in an HTTP header.
  6. A second HTTPS request fetches an HTML-formatted response, from which the malware extracts a hex-encoded secondary payload using regular expressions.
  7. The extracted binary is decoded and installed into a directory within %LOCALAPPDATA%.
  8. Persistence is established via scheduled tasks or Windows Registry Run keys to execute the installed payload.

Impact

UAC-0099 targets Ukrainian governmental, financial, and media organizations. Successful compromise leads to the installation of backdoors like MATCHWOK, enabling unauthorized remote access, data exfiltration, and potential facilitation of further malicious operations by related threat groups such as Sandworm.

Recommendation

  • Monitor endpoint telemetry for VBScript processes spawning child processes or network connections, which may indicate the initiation of the MATCHBOIL infection chain.
  • Implement Sigma rules to detect suspicious WMI query patterns (e.g., CPUID, BIOS serial number retrieval) and unexpected registry modifications in the 'Run' key.
  • Block and monitor traffic to the C2 domains provided in the IOC table at the network perimeter.
  • Deploy detections for the execution of .NET-based binaries that exhibit code obfuscation or rely on non-standard HTTP header structures for C2 communication.

Immediate actions

Block the identified C2 domains and IPs in firewall and DNS egress policies.

SOC 24h

Threat Hunt

Search for VBScript files executed from temporary directories or user profiles.

T1059.005 high high confidence hunt now

Data: Process creation logs showing script execution

Detection coverage 1

Detect MATCHBOIL Persistence via Registry Run Key

medium

Detects potential MATCHBOIL persistence mechanisms via modifications to the Windows Registry Run key.

sigma tactics: persistence techniques: T1547.001 sources: registry_set, windows

Detection queries are available on the platform. Get full rules →

Indicators of compromise

2

domain

2

ip

TypeValue
domainvirtualdailyplanner.pro
domaintelemetry-conf.com
ip64.95.10.223
ip64.95.13.210