Skip to content

Response, New York. Noah Park: Check Point Patches Actively Exploited Management Server Path Traversal. Detection, Dallas. Ava Okello: Report Finds Nearly Half of Deployed Detections Need Attention Before SOCs Can Trust Them.

SOCtember

Always First. Fast SOC News.

A small Windows application window titled Dairy with the heading DailyPlanner, a date picker reading Wednesday, April 22, 2026, two text boxes each labeled Today containing keyboard gibberish, and a large photo of an orange tabby kitten with its mouth wide open.
Screenshot: ESET Research, the fake daily planner window, titled Dairy, that late 2025 MATCHBOIL samples display when opened directly, from MATCHBOIL: New tricks, same old evil intentions, Oct 8, 2026 (fair use).

Threat Intel

Russia-Aligned Spies Retool MATCHBOIL Malware and Widen Attacks to Ukrainian Transport, Manufacturing and Energy Firms

ESET says UAC-0099, a group it describes as able to act as an initial access broker for Sandworm, planted its rebuilt MATCHBOIL downloader at Ukrainian transportation, manufacturing and energy companies, adding fake planner screens, sandbox checks and a new DLL variant while leaving a trail of file paths, scheduled tasks and HTTP headers defenders can hunt.

Priya Shah, Threat IntelSingapore6 min read

SINGAPORE - A Russia-aligned espionage group that has long gone after Ukrainian government agencies has been planting a steadily rebuilt piece of malware inside Ukrainian transportation, manufacturing and energy companies, according to research published on Thursday by the Slovak security company ESET. Every victim of the downloader, which ESET and Ukraine's government computer emergency response team, CERT-UA, call MATCHBOIL, that ESET found in its own telemetry was in Ukraine: multiple transportation companies in July and August 2025, a manufacturing company in December 2025 and a company in the energy sector in June 2026. ESET describes the group, tracked as UAC-0099, as a cyberespionage operation targeting government organizations, financial institutions and media in Ukraine, and says it "can act as an initial access broker for Sandworm," the Russia-aligned group known for destructive attacks on Ukraine.

The infection begins with an ordinary lure. According to ESET's analyst Fernando Tavella, the group sends spearphishing emails with a malicious link that downloads an archive holding a VBScript file; the victim has to be talked into running the script by hand, and the script then downloads and runs MATCHBOIL. The downloader, written in C#, fingerprints the machine through Windows Management Instrumentation queries, collecting the CPUID and BIOS serial number and, in later versions, the username, the network card's MAC address and the computer's model and manufacturer. It then makes three HTTPS requests to its command server: one returns a number, one returns HTML with a hex-encoded payload that MATCHBOIL pulls out with a regular expression such as <script>(.*?)</script>, and one returns a string saved as a configuration file. In most cases, ESET said, the payload is MATCHWOK, a C# backdoor used only by UAC-0099. "For example, it can take screenshots of the victim desktop or execute PowerShell commands on the victim's computer," Mr. Tavella told Help Net Security.

Decompiled C# code for a method named get_BasicVictim_Info that uses ManagementObjectSearcher to run the WMI query SELECT ProcessorId FROM Win32_Processor and return the result.
Screenshot: ESET Research, decompiled MATCHBOIL routine that fingerprints the victim machine through a WMI query for the processor ID, Oct 8, 2026 (fair use).MATCHBOIL reads the processor ID through WMI.

ESET said it began looking at MATCHBOIL in February 2026, when two samples uploaded to VirusTotal were seen talking to a domain previously attributed to UAC-0099. That led it to more samples in its own telemetry, some compiled in April 2024. CERT-UA first documented MATCHBOIL in August 2025, but ESET said compilation timestamps suggest the group was already developing it in 2024. Over roughly two years, ESET said, the operators turned a one-shot downloader into one that checks in with its server every two minutes, swapped custom string encryption and unprintable Unicode names for the Eziriz .NET Reactor obfuscator, and switched persistence from a registry value plus a scheduled task, to a Run key alone, and then to a scheduled task.

The newer builds also try to fool both people and sandboxes. Samples from late 2025 show a fake daily planner if someone opens the file directly; ESET noted that the window's title is misspelled "Dairy," which it said suggests planning one's milk product intake, and that both text boxes are labeled "Today." The malicious code runs only when the file is launched with the argument -auto, after which it creates the mutex Global\PlannerAssistant. Before calling home, it reads Windows System event 6013, which records uptime, using one regular expression in English and one in Russian, and proceeds only if at least three events show uptime of 7,200 seconds or more. It also checks whether a debugger is attached. A February 2026 sample added the argument -plans; another that month used -renew and swapped the planner for a fake regular expression search tool. An April 2026 variant, which CERT-UA calls MATCHBOIL.V2, is the first delivered as a DLL run by a custom C# loader, and it adds a check on how long ago the operating system was installed, with a 10-day threshold.

A Windows desktop showing a Notepad file named eset.txt with words containing ESET next to a small Regex Finder window whose pattern field searches for words containing ESET and lists the matches.
Screenshot: ESET Research, the regular expression search tool shown by a February 2026 MATCHBOIL sample in place of the planner, Oct 8, 2026 (fair use; username redacted by ESET).A February sample showed a fake regular-expression tool instead of the planner.

For defenders, ESET's write-up is mostly a list of places to look, and the names change with each version. The 2024 builds installed their payload under %LOCALAPPDATA%\DeviceMonitor with a config.ini file, set a Run value named DeviceMonitor under HKCU\Software\Microsoft\Windows\CurrentVersion\Run and created a scheduled task named Updates\CheckTask. The late 2025 builds dropped the payload at %LOCALAPPDATA%\MeowCheck\MeowMeowProgramm.exe, wrote a temporary file named WallpappersSet.jpg to the user's Pictures folder, saved configuration as config.library-ms under C:\Users\Public\Libraries and created a task named UpdateCheckers\DailyPlanner that runs every seven minutes. The April 2026 variant installs %LOCALAPPDATA%\SMTPClient\SMTPClientApplication.exe and persists through a task named Checker under a MailClient folder. ESET also listed the payload file name Thumbs.db as a masquerading technique.

On the network side, the builds ESET described send a custom HTTP header named SN carrying the victim fingerprint and a 25-character User-Agent string; the numeric value from the first request travels in a header named Count in 2024 builds and Answer in late 2025 builds. ESET said the group hosts command servers on virtual private servers such as BitLaunch, hides them behind Cloudflare and uses Let's Encrypt certificates that are not reused across domains. Its published indicators include the domains virtualdailyplanner[.]pro and telemetry-conf[.]com, flycloud-service[.]com at 64.95.10[.]223 and airarticlegenerate[.]com at 64.95.13[.]210, along with SHA-1 hashes such as 050926727CDD74F0B3A8A098E60B76D10FB06B14 for the April 2026 sample. The full list is in ESET's malware-ioc repository on GitHub.

Two blocks of decompiled C# code outlined in red. The top method, SendResultRequest, builds a GET request to an eventmanager path with SN and Answer headers; the bottom method, query_2_CnC, sends SN, User-Agent and Count headers and extracts the payload with a regular expression for script tags.
Screenshot: ESET Research, the second command server request in a late 2025 MATCHBOIL sample (top, Answer header) compared with a 2024 sample (bottom, Count header), Oct 8, 2026 (fair use).Later builds send the first reply in an Answer header instead of Count.

ESET's report lands three days after researchers at TrendAI published their own history of an overlapping intrusion set, which it says has run spearphishing campaigns since at least 2022 against Ukrainian government, defense, border guard and logistics targets using more than 10 malware families. TrendAI described a previously undocumented .NET information stealer and remote access tool it calls ASHVEIN, and a July 2026 chain documented by CERT-UA in which a malicious Notepad++ plugin, LUNCHPOKE, deploys a .NET loader called BURNYBEAR and MATCHBOIL.V2. TrendAI said most confirmed command domains used the registrar Regery.com and Cloudflare, with backend servers clustered in AS399629, BL Networks, the same provider ESET lists for two of its IP addresses. TrendAI's advice includes watching for executables created under C:\Users\Public\Libraries, renamed copies of schtasks.exe and Notepad++ loading DLLs from unusual plugin locations, and it said its own telemetry showed activity against transport and logistics operators.

ESET's attribution is hedged. It said it believes with medium confidence, based on targeting, that UAC-0099 is aligned with Russian interests, and it describes the Sandworm link as a role the group can play rather than tying any of the new victims to a destructive attack. Mr. Tavella said the widening list of victims could be deliberate. "UAC-0099 has been targeting different entities in Ukraine. We believe that the group has different interests and their expansion in the victimology could mean that they are seeking to maximise their impact in UA," he told Help Net Security. "Let's remember that this group has been an initial access broker of Sandworm, another Russia-aligned APT group, so it is possible they are seeking victims that can be of interest for other APT groups that UAC-0099 can assist." ESET, which sells private threat intelligence reports, did not name the victim companies or say whether any data was taken.

Sources:


Priya Shah covers threat intelligence, intrusion analysis, and adversary tradecraft for SOCtember from Singapore.

Related stories

Threat Intel desk