ESET has published an analysis of MATCHBOIL, a custom C# downloader used by the group it tracks as UAC-0099. The useful finding is not what the tool does, which is ordinary. It is how long it has been doing it.

CERT-UA first documented MATCHBOIL in August 2025. ESET's collection of samples carries compile timestamps running from April 2024 to April 2026, and it reads CERT-UA's own samples as built in mid-2024. The conclusion is that the group was developing this a year or more before anyone wrote about it.

That gap is the finding. Public documentation of a tool marks the date somebody noticed, not the date it started working.

What it is and how it arrives

The delivery is unglamorous and effective. A spearphishing email carries a link, the link fetches an archive, the archive holds a VBScript, and the victim has to run it. No exploit, no zero-day — a person opening a file.

The VBScript fetches and runs MATCHBOIL and sets up persistence for a loader that will run it again. MATCHBOIL's own job is narrow: check for a marker directory under the local application data folder, exit if it is already there, otherwise pull a payload from the command server, install it, and persist it with a scheduled task or a registry value.

The payload is usually MATCHWOK, a C# backdoor ESET describes as used exclusively by this group.

Two timers, frequently confused

One detail is worth separating, because the numbers travel badly.

The 2024 builds ran once. Fetch, install, done.

By late 2025, MATCHBOIL sets a timer that runs its command-server logic every two minutes, so the operator can swap in a new payload and have it picked up almost immediately. That is a meaningful change: it turns a one-shot dropper into something closer to a standing channel.

The seven-minute interval that also appears in ESET's write-up is the scheduled task used for persistence — a different mechanism doing a different job. The two get reported as one figure, and they are not.

The analyst checks

The later builds are built to be boring to a researcher.

Through 2024 the obfuscation was homemade: class and method names renamed with unprintable Unicode symbols, strings encrypted with a custom routine. By late 2025 the group had moved to a commercial .NET obfuscator with code virtualisation and control-flow obfuscation, which is a different class of nuisance.

The evasion is more interesting than the obfuscation. Late-2025 builds read Windows uptime events and require at least three events with an uptime value of at least 7,200 seconds before deciding they are on a real machine — a two-hour floor that a disposable sandbox rarely clears. They also check for an attached debugger.

In April 2026 a check appeared that compares the operating system's install date against the date the sample is running. ESET's description reads as refusing to run when the install predates execution by ten days or more, which would exclude most genuine targets — so either the check is narrower than it sounds or the description compresses it. We are flagging it rather than explaining it.

Who, and how confident

ESET observed every victim in Ukraine: transport companies in July and August 2025, a manufacturer in December 2025, an energy-sector company in June 2026. Three sectors over eleven months, all of them infrastructure.

On the group itself, ESET says it believes with medium confidence that UAC-0099 is aligned with Russian interests. Medium confidence is not a formality, and it does not become high confidence by being repeated.

ESET also says UAC-0099 can act as an initial access broker for Sandworm — the group associated with destructive attacks in Ukraine. That phrasing is careful. It describes a capability and a relationship, not a chain of command, and the distance between "can act as" and "acts on behalf of" is the distance between a supplier and a subordinate.

The group's other tool is LONEPAGE, a PowerShell downloader named for a string in its command-server URLs.

What to do

  • The entry point is a script a person runs from an emailed archive. Blocking script execution from archive and download paths closes this specific chain regardless of what the payload becomes.
  • Look for the marker directory pattern under local application data, and for scheduled tasks and run keys created shortly after an archive was opened.
  • A two-minute poll to a fixed host is a visible pattern in outbound logs. Regularity is the signal here, not volume.
  • If you are in transport, manufacturing or energy in or adjacent to Ukraine, treat this as current. The June 2026 victim is the most recent ESET names.

What is not established

  • What MATCHWOK actually does once installed. ESET names it and does not describe its capabilities in this write-up.
  • Whether the April 2026 install-date check works the way its description reads.
  • How the group selects targets, and how many victims exist outside ESET's telemetry.
  • Whether any of the observed intrusions led to Sandworm activity, as opposed to UAC-0099 having the capability to hand one over.
  • Who UAC-0099 is. Medium confidence on alignment with Russian interests is the most ESET says.