MATCHBOIL: how UAC-0099 gets into Ukrainian infrastructure
ESET traced two years of MATCHBOIL, the downloader UAC-0099 used against Ukrainian transport, manufacturing and energy firms. How it works and how to hunt it.
By Yaali. October 11, 2026, 6 min read, Threat intel, Phishing, Windows.
On October 8, ESET published a study of MATCHBOIL, a C# downloader used by UAC-0099, a group that has spied on Ukrainian government bodies, banks and media since at least 2022. ESET's telemetry shows MATCHBOIL on the networks of Ukrainian transportation companies in July and August 2025, a manufacturer in December 2025 and an energy company in June 2026. Every victim ESET saw was in Ukraine, and ESET has not said how many there were.
The tool matters beyond Ukraine for two reasons. ESET says UAC-0099 can act as an initial access broker for Sandworm, the Russian military intelligence unit behind attacks on Ukraine's power grid, so a MATCHBOIL infection may be the first step toward something worse. And every technique it uses (a script in an archive, a fake plugin, scheduled tasks, frequent HTTPS check-ins) is one a Windows estate anywhere can detect with standard logging. ESET attributes UAC-0099 to Russian interests with medium confidence, based on who it targets.

How it works
The chain starts with a spear-phishing email holding a link. The link downloads an archive containing a VBScript file, and the victim has to be talked into opening it. The script, run by the Windows Script Host (wscript.exe), downloads and starts MATCHBOIL.
MATCHBOIL first checks for its own folder under %LOCALAPPDATA%. If the folder exists, the machine is already infected and it exits. Otherwise it builds a victim ID from the CPU ID and BIOS serial number, then makes three HTTPS requests to its command and control (C2) server. The second response looks like an HTML page, with the payload hidden inside it as hex-encoded text, so a quick look at the traffic shows an ordinary web page. MATCHBOIL decodes the payload, writes it into its folder and sets it to start again at every logon through a scheduled task or a Run registry key.
In most cases the payload is MATCHWOK, a C# backdoor that UAC-0099 alone uses. It can take screenshots of the desktop and run PowerShell commands. In the August 2025 campaign that CERT-UA, Ukraine's national computer emergency response team, documented, MATCHBOIL also delivered DRAGSTARE, a stealer that takes browser passwords and cookies and files from the victim's desktop.
The folder names change with each version: DeviceMonitor in 2024, MeowCheck\MeowMeowProgramm.exe in late 2025 and SMTPClient\SMTPClientApplication.exe in April 2026, when persistence moved to a scheduled task named Checker in a task folder called MailClient. Hunting for one exact name will miss the next build, which is why the checks below look for behaviour.
How it got harder to catch
ESET found samples compiled as early as April 2024, more than a year before CERT-UA first described MATCHBOIL in August 2025. Each version added something:
- Early builds were one-shot downloaders. From late 2025, the C2 logic runs on a timer every two minutes, so a failed first contact no longer ends the infection.
- The homemade string encryption was replaced with Eziriz .NET Reactor, a commercial obfuscator that virtualises code and scrambles control flow, which slows reverse engineering.
- A sandbox check reads Windows event logs for uptime records (Event ID 6013), with patterns for both English and Russian Windows. It only continues if at least three records show 7,200 seconds (two hours) or more of uptime, a test aimed at analysis machines that are booted only for a few minutes.
- The April 2026 build also quits if Windows was installed fewer than ten days before it runs, another sign of a fresh analysis machine.
- Late 2025 builds show a fake daily planner if someone launches the file by hand, so a curious user or analyst sees a harmless app.
The infrastructure follows the same habits. UAC-0099 rents servers from VPS providers such as BitLaunch, puts them behind Cloudflare and uses Let's Encrypt certificates, which ESET found are not reused across domains.
The Notepad++ variant
The April 2026 build is a DLL that CERT-UA calls MATCHBOIL.V2. In a July 2026 advisory, CERT-UA described how it arrived: the VBScript fetched a second archive containing a working copy of Notepad++ with a malicious NppExport.dll in its plugins\NppExport\ folder, a password-protected RAR and its own copy of WinRAR. Notepad++ loads plugins at startup, so the victim sees the editor open normally while the DLL, which CERT-UA calls LUNCHPOKE, unpacks RemoteLibUpdater.exe and InitTest.dll (MATCHBOIL.V2) and creates a scheduled task that runs every three minutes. No vulnerability in Notepad++ is involved; the attackers ship their own copy.
What to do

1. Stop the first stage
Most users have no reason to run VBScript. Turn on the Microsoft Defender attack surface reduction rule "Block JavaScript or VBScript from launching downloaded executable content" (GUID d3e037e1-3eb8-44c8-a917-57927947596d), in audit mode first if you are unsure what depends on scripts. Where you can, go further and change the default handler for .vbs and .vbe files to Notepad through Group Policy, so a double-click opens the text instead of running it. CERT-UA also advises keeping WinRAR, 7-Zip and Notepad++ up to date.
2. Hunt for the script stage
In your EDR or Sysmon process creation logs (Sysmon Event ID 1), look for wscript.exe or cscript.exe whose command line points inside an archive extraction folder, such as %TEMP%\Rar$*, %TEMP%\7z* or a Temp1_*.zip folder from the built-in Windows zip handler. Follow any hit to its child processes and outbound connections.
3. Check persistence
List scheduled tasks with Get-ScheduledTask | Where-Object { $_.Actions.Execute -like '*AppData*' } and review every task that runs from a user profile or repeats every few minutes. Turn on "Audit Other Object Access Events" so new tasks are logged as Security Event ID 4698, and check HKCU\Software\Microsoft\Windows\CurrentVersion\Run for values pointing into %LOCALAPPDATA%.
4. Look for stray Notepad++ copies
A real installation lives under C:\Program Files\Notepad++. Search for notepad++.exe and NppExport.dll anywhere else, especially in Downloads, Temp and Documents, and use Sysmon Event ID 7 (image loaded) to flag notepad++.exe loading a plugin DLL from outside Program Files.
5. Watch egress
An unsigned executable in a user profile making HTTPS requests every two minutes, to a domain registered recently and fronted by Cloudflare, is worth a closer look whatever malware it turns out to be. Proxy logs grouped by source host and destination, with a check on request intervals, will surface it. ESET's report lists file hashes and C2 domains for direct blocking.
If you find an infection, treat the machine as a possible handover point. Rebuild it, reset the passwords and browser sessions of its users (DRAGSTARE takes cookies, which can bypass multi-factor authentication), and review what that account reached in the weeks before.
The wider lesson
Organisations that work with Ukrainian transport, energy or manufacturing partners, or supply them, sit close to this activity. The detections here do not depend on knowing UAC-0099's next file name: script hosts launched from archives, portable applications loading plugins from user folders and short-interval beacons are rare on a well-run estate and cheap to alert on.
Our security operations team builds detections like these and hunts for them across endpoints and proxy logs, and our safeguarding and hardening work locks down script hosts and attack surface reduction rules without breaking line-of-business tools. Open the chat and Yaali, our AI agent, will pass your question to an engineer.
Sources: ESET WeLiveSecurity, Help Net Security, The Record, Dark Reading, Security Affairs on CERT-UA's Notepad++ advisory, The Hacker News, CERT-UA.
Read next
- LunexStealer: blockchain-steered fake Cloudflare checks
- ClickFix hides its payload in the browser cache
- Fake invites that install MSP360, then ScreenConnect
Back to the blog, or tell us about your system in the chat. Yaali, our AI agent, answers first and brings in an engineer.