Full Report
ESET Research catalogs the changes of UAC-0099’s MATCHBOIL downloader from 2024 to 2026
Analysis Summary
# Threat Actor: UAC-0099
## Attribution & Identity
* **Actor Name:** UAC-0099
* **Alignment:** Russia-aligned (medium confidence).
* **Known Associations:** Identified as a potential initial access broker for **Sandworm** (a Russia-aligned group known for destructive attacks).
* **Status:** Active since at least 2022; first reported by CERT-UA in June 2023.
## Activity Summary
The actor has been consistently evolving its custom C# downloader, **MATCHBOIL**, with development activity traced back to April 2024. Recent campaigns documented between 2024 and 2026 show a progression from simple code to sophisticated obfuscation and evasion techniques. The actor utilizes spearphishing emails containing malicious links to deliver VBScript payloads, which subsequently deploy MATCHBOIL to establish persistence and download further payloads.
## Tactics, Techniques & Procedures
* **Native API Execution:** Uses Windows APIs for C2 communication (T1106).
* **WMI Discovery:** Utilizes WMI queries to gather CPUID, BIOS serial numbers, and system info (T1047).
* **Persistence:**
* Registry Run Keys (T1547.001).
* Scheduled Tasks (T1053.005).
* **Evasion & Stealth:**
* **Anti-Sandboxing:** Queries Windows event logs to detect sandbox environments (T1497.001).
* **Debugger Evasion:** Checks if attached to a debugger (T1622).
* **Obfuscation:** Transitioned from Unicode symbol renaming to **Eziriz .NET Reactor** obfuscator.
* **Execution Delay:** Uses Sleep API to hinder analysis (T1678).
* **Masquerading:** Names payloads as legitimate files like `Thumbs.db` (T1036.005).
* **C2 Communication:**
* HTTPS/TLS encryption (T1573.002, T1071.001).
* Hex encoding for payload delivery (T1132.001).
## Targeting
* **Sectors:** Transportation, Manufacturing, Energy, Governmental organizations, Financial institutions, and Media.
* **Geography:** Primarily Ukraine.
* **Victims:** Multiple unnamed transportation companies, manufacturing firms, and energy sector entities within Ukraine.
## Tools & Infrastructure
* **Malware Families:**
* **MATCHBOIL:** Custom C# downloader.
* **LONEPAGE:** PowerShell downloader.
* **Infrastructure:**
* **C2 Communication:** Uses HTTPS/TLS for command and control.
* **Distribution:** Malicious VBScript files hosted via links in spearphishing emails.
* **Attributed Domains:** Communication established with domains previously linked to UAC-0099 activity (specific URLs defanged in ESET telemetry).
## Implications
UAC-0099 represents a persistent threat to Ukrainian critical infrastructure. Their role as a potential initial access broker for Sandworm suggests that their activity is often a precursor to more destructive operations. The continuous development of MATCHBOIL—moving from simple scripts to highly obfuscated, sandbox-aware malware—indicates a dedicated resource pool and a high level of technical maturity aimed at evading modern EDR and sandbox detections.
## Mitigations
* **Email Filtering:** Implement robust scanning for spearphishing attempts, particularly those containing links to archive files or VBScripts.
* **Endpoint Monitoring:** Monitor for suspicious WMI queries and unauthorized modifications to Registry Run keys or the creation of new Scheduled Tasks.
* **Behavioral Analysis:** Deploy security solutions capable of detecting "Sleep" API abuse and sandbox evasion techniques (e.g., event log querying).
* **Access Control:** Restrict the execution of VBScript and PowerShell on end-user devices where not business-essential.
* **Indicator Blocking:** Monitor and block communication with known UAC-0099 C2 infrastructure and domains associated with LONEPAGE and MATCHBOIL.