<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Downloader - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/downloader/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 09 Oct 2026 07:56:08 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/downloader/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Evolution of UAC-0099's MATCHBOIL Downloader</title><link>https://feed.craftedsignal.io/briefs/2026-10-matchboil/</link><pubDate>Fri, 09 Oct 2026 07:56:08 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-matchboil/</guid><description>UAC-0099, a Russia-aligned threat actor, uses the evolving MATCHBOIL C# downloader to target Ukrainian sectors via spearphishing and secondary payload delivery.</description><content:encoded><![CDATA[<p>UAC-0099, a Russia-aligned cyberespionage group active since at least 2022, has been systematically evolving the MATCHBOIL downloader since April 2024. MATCHBOIL is a custom C# malware designed to download, install, and persist subsequent payloads, such as the MATCHWOK backdoor. Initially a straightforward one-shot downloader, the malware has matured to include sophisticated obfuscation via the Eziriz .NET Reactor, multi-stage execution on timers, and sandbox evasion techniques. ESET researchers have identified victims across various Ukrainian sectors, including transportation, manufacturing, and energy. The actor frequently acts as an initial access broker for other groups, including Sandworm. Defenders should monitor for suspicious C# binaries, unusual VBScript execution, and irregular HTTPS traffic patterns associated with identified C2 domains.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>The attacker sends spearphishing emails containing links to an archive file.</li>
<li>The victim downloads and manually executes a VBScript payload contained within the archive.</li>
<li>The VBScript downloads and executes the MATCHBOIL downloader binary.</li>
<li>MATCHBOIL performs environment checks, including WMI queries and sandbox detection, to verify the execution environment.</li>
<li>MATCHBOIL initiates an HTTPS connection to the C2 server to retrieve a command identifier in an HTTP header.</li>
<li>A second HTTPS request fetches an HTML-formatted response, from which the malware extracts a hex-encoded secondary payload using regular expressions.</li>
<li>The extracted binary is decoded and installed into a directory within %LOCALAPPDATA%.</li>
<li>Persistence is established via scheduled tasks or Windows Registry Run keys to execute the installed payload.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>UAC-0099 targets Ukrainian governmental, financial, and media organizations. Successful compromise leads to the installation of backdoors like MATCHWOK, enabling unauthorized remote access, data exfiltration, and potential facilitation of further malicious operations by related threat groups such as Sandworm.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Monitor endpoint telemetry for VBScript processes spawning child processes or network connections, which may indicate the initiation of the MATCHBOIL infection chain.</li>
<li>Implement Sigma rules to detect suspicious WMI query patterns (e.g., CPUID, BIOS serial number retrieval) and unexpected registry modifications in the 'Run' key.</li>
<li>Block and monitor traffic to the C2 domains provided in the IOC table at the network perimeter.</li>
<li>Deploy detections for the execution of .NET-based binaries that exhibit code obfuscation or rely on non-standard HTTP header structures for C2 communication.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">threat</category><category>malware</category><category>downloader</category><category>csharp</category><category>uac-0099</category><category>ukraine</category></item></channel></rss>