Cyber-espionage activity linked to the Russia-aligned group UAC-0099 is updating its MATCHBOIL malware, described as a downloader/dropper used in campaigns targeting Ukrainian organizations. Multiple outlets report that the malware receives ongoing refinements aimed at improving how it operates on victim systems.
ESET researchers, cited by one outlet, trace changes to MATCHBOIL over nearly two years and report that the second-stage program it installs functions as a spying backdoor. Reported victim activity appears concentrated in Ukraine across a range of sectors, including transportation, manufacturing, and energy. While Dark Reading and Infosecurity Magazine focus on the “stealthy facelift” and continued evolution since at least 2024, the Help Net Security piece emphasizes what MATCHBOIL does and summarizes telemetry timelines and targeted industries based on ESET’s observations.