{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/downloader/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":["UAC-0099"],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":[],"_cs_severities":["high"],"_cs_tags":["malware","downloader","csharp","uac-0099","ukraine"],"_cs_type":"threat","_cs_vendors":[],"content_html":"\u003cp\u003eUAC-0099, a Russia-aligned cyberespionage group active since at least 2022, has been systematically evolving the MATCHBOIL downloader since April 2024. MATCHBOIL is a custom C# malware designed to download, install, and persist subsequent payloads, such as the MATCHWOK backdoor. Initially a straightforward one-shot downloader, the malware has matured to include sophisticated obfuscation via the Eziriz .NET Reactor, multi-stage execution on timers, and sandbox evasion techniques. ESET researchers have identified victims across various Ukrainian sectors, including transportation, manufacturing, and energy. The actor frequently acts as an initial access broker for other groups, including Sandworm. Defenders should monitor for suspicious C# binaries, unusual VBScript execution, and irregular HTTPS traffic patterns associated with identified C2 domains.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe attacker sends spearphishing emails containing links to an archive file.\u003c/li\u003e\n\u003cli\u003eThe victim downloads and manually executes a VBScript payload contained within the archive.\u003c/li\u003e\n\u003cli\u003eThe VBScript downloads and executes the MATCHBOIL downloader binary.\u003c/li\u003e\n\u003cli\u003eMATCHBOIL performs environment checks, including WMI queries and sandbox detection, to verify the execution environment.\u003c/li\u003e\n\u003cli\u003eMATCHBOIL initiates an HTTPS connection to the C2 server to retrieve a command identifier in an HTTP header.\u003c/li\u003e\n\u003cli\u003eA second HTTPS request fetches an HTML-formatted response, from which the malware extracts a hex-encoded secondary payload using regular expressions.\u003c/li\u003e\n\u003cli\u003eThe extracted binary is decoded and installed into a directory within %LOCALAPPDATA%.\u003c/li\u003e\n\u003cli\u003ePersistence is established via scheduled tasks or Windows Registry Run keys to execute the installed payload.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eUAC-0099 targets Ukrainian governmental, financial, and media organizations. Successful compromise leads to the installation of backdoors like MATCHWOK, enabling unauthorized remote access, data exfiltration, and potential facilitation of further malicious operations by related threat groups such as Sandworm.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMonitor endpoint telemetry for VBScript processes spawning child processes or network connections, which may indicate the initiation of the MATCHBOIL infection chain.\u003c/li\u003e\n\u003cli\u003eImplement Sigma rules to detect suspicious WMI query patterns (e.g., CPUID, BIOS serial number retrieval) and unexpected registry modifications in the 'Run' key.\u003c/li\u003e\n\u003cli\u003eBlock and monitor traffic to the C2 domains provided in the IOC table at the network perimeter.\u003c/li\u003e\n\u003cli\u003eDeploy detections for the execution of .NET-based binaries that exhibit code obfuscation or rely on non-standard HTTP header structures for C2 communication.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-09T07:56:08Z","date_published":"2026-10-09T07:56:08Z","id":"https://feed.craftedsignal.io/briefs/2026-10-matchboil/","summary":"UAC-0099, a Russia-aligned threat actor, uses the evolving MATCHBOIL C# downloader to target Ukrainian sectors via spearphishing and secondary payload delivery.","title":"Evolution of UAC-0099's MATCHBOIL Downloader","url":"https://feed.craftedsignal.io/briefs/2026-10-matchboil/"}],"language":"en","title":"CraftedSignal Threat Feed - Downloader","version":"https://jsonfeed.org/version/1.1"}