1. Overview
- Article Title: MATCHBOIL: New tricks, same old evil intentions
- Publisher: ESET Research
- Publication Date: 2026-10-08
- Original Source: ESET Research
- Related Source: The Record
- Related Malware and Threat Groups: MATCHBOIL, MATCHWOK, LONEPAGE, UAC-0099
- Related CVE: None specified
- Related Products: Windows
- Severity: High
2. Quick Summary
UAC-0099 delivers VBScript via spearphishing links, executes the C# downloader MATCHBOIL to retrieve hex payloads embedded in HTML, and establishes persistence for the MATCHWOK backdoor using scheduled tasks or Run keys.
3. Attack Flow
From Spearphishing to MATCHWOK
- The attacker sends a spearphishing email containing a malicious link.
- The user manually executes a VBScript inside an archive, which downloads and executes MATCHBOIL.
- In later variants, sandbox and debugger checks precede C2 communication. When the checks permit execution, C2 communication runs on a two-minute timer.
- MATCHBOIL collects system information and sends three HTTPS requests to retrieve a numeric value, an HTML-embedded hex payload, and potential payload configuration.
- It decodes and installs the payload and establishes persistence using a Run key or scheduled task. The method and timing of payload execution vary by version.
4. Attacker Positioning and Execution Location
- External attackers targeting Windows endpoints of Ukrainian organizations via email and the web.
5. Victim and Administrator Perspective
- Users: Victims are prompted to run a VBScript from an archive. Some MATCHBOIL variants display a decoy planner or text-search interface when launched without the arguments that activate their malicious behavior.
- Administrators: Visible artifacts include WSH processes, WMI queries, three-stage HTTPS requests, scheduled tasks, and the MATCHWOK payload.
6. Success and Failure Conditions
Success Conditions
- The user executes the VBScript inside the archive.
- The endpoint successfully connects to the C2 server via HTTPS and saves and executes the payload.
Failure Conditions and Countermeasures
- Block mail links, archives, and scripts, and restrict WSH.
- Prevent C2 communications, payload writes, and the creation of scheduled tasks or Run keys.
7. What Happens Upon Success
- Installation and persistence of backdoors such as MATCHWOK.
- System information collection and remote command execution capabilities.
- Potential progression to additional malware, credential theft, and data exfiltration.
8. Observable Logs
These are investigation candidates for your organization and do not imply that all events were observed in this specific incident.
- Email: Check for Ukraine-themed spearphishing links, archive downloads, and sender or URL reputation.
- Proxy / SWG / DNS: Verify the three HTTPS requests, hex blobs within HTML responses, two-minute beacon intervals, and associated domains.
- Endpoint / EDR: Check for wscript/cscript, C# loaders, WMI, Run keys, scheduled tasks, WallpappersSet.jpg, and SMTPClientApplication.exe.
- Identity / IdP: Verify unusual logins, token and credential use, privilege changes, and service account manipulation.
- SaaS / Cloud: Monitor management APIs, audit logs, repository or cloud resource access, and large-scale downloads.
- Network: Check for domains behind Cloudflare, BitLaunch VPS, and regular two-minute beacons.
9. Attack Success Determination
Confirmed in Public Information
- MATCHBOIL Observed: ESET reported MATCHBOIL detections in its telemetry at Ukrainian transportation, manufacturing, and energy enterprises.
- Capabilities Confirmed via Analysis: MATCHBOIL has the capability to retrieve, install, and persist payloads such as MATCHWOK. The scope of subsequent payload execution, successful persistence, and data theft in individual victim environments has not been publicly disclosed.
Determination Criteria for Your Organization
- Subsequent Compromise Confirmed: Verify the execution of subsequent payloads and persistence settings on the target host. Do not infer successful subsequent execution based solely on downloader detection or payload retrieval requests.
- Correlate requests, processes, authentication, data access, and outbound transmissions to distinguish between attack attempts and successes.
- Do not determine success from HTTP status codes or isolated alerts alone; corroborate them with evidence from the affected environment.
10. Investigation Playbook
- Investigation Starting Point: Start with the spearphishing archive, VBScript, MATCHBOIL hash, associated C2 servers, and scheduled tasks.
- Initial Verification: Check target products, versions, configurations, external reachability, exposure duration, and update/containment timestamps.
- Endpoint / Server Investigation: Verify archives, scripts, process trees, WMI, payload files, Run keys, scheduled tasks, and event log access.
- Authentication / Cloud Investigation: Track suspicious accounts, tokens, API usage, privilege changes, unusual connection sources, and resource access.
- Subsequent Actions: Follow up on credential access, lateral movement, additional downloads, outbound transmissions, and account creation after the initial event.
- Containment: Isolate endpoints, block C2 servers, preserve and then remove persistence and payloads, and rotate credentials.
- Judgment Categories: Distinguish between reconnaissance/attack attempts, initial execution, successful authentication, data theft, and subsequent compromise.
11. Defense and Detection Ideas
- Single Events: Detect C# binary launches from VBScript, SMTPClientApplication.exe, and listed tasks or domains.
- Temporal Correlation: Correlate mail links -> archives -> VBScript -> MATCHBOIL -> 3 HTTPS requests -> payloads -> persistence.
- Threat Hunting: Search for ESET IoCs, two-minute beacons, WMI system discovery, and Run keys or scheduled tasks.
- Log Limitations: TLS and Cloudflare may obscure payloads or origins, making endpoint telemetry necessary.
- Priority Countermeasures: Prioritize email URL defenses, script controls, EDR, egress filtering, and user training.
12. Facts / Inference / Hypothesis
Facts
- A malicious link in a spearphishing email leads to an archive containing a VBScript. When the victim manually runs the script, it downloads and executes MATCHBOIL.
- The loader collects CPUID, BIOS serial numbers, MAC addresses, and other details, issuing three HTTPS requests to retrieve an ID, hex payload within HTML, and configuration.
- In many observations, the payload was MATCHWOK, a C# backdoor exclusive to UAC-0099. It achieves persistence via Run keys or scheduled tasks.
- Late-2025 variants check system uptime recorded in Windows event logs and debuggers, repeating C2 communications on a two-minute timer if conditions are met. Additional checks using OS installation dates were confirmed in an April 2026 DLL version.
- ESET observed MATCHBOIL at Ukrainian transportation, manufacturing, and energy enterprises. All observed victims were located in Ukraine.
- Based on targeting, ESET assesses with medium confidence that UAC-0099 is aligned with Russian interests and could serve as an initial access broker for Sandworm.
Inference
- Combining three-stage HTTPS, HTML hex payloads, scheduled task names, and WMI system discovery provides stronger resilience against variant changes.
- While direct targeting of Japanese organizations has not been confirmed, organizations involved in Ukraine-related business, logistics, and energy supply chains should account for similar spearphishing themes.
Hypothesis
No additional hypotheses. Unverified items are documented in "14. Unknowns and Additional Investigations".
13. MITRE ATT&CK Mapping
| ID | Technique | Confidence | Basis |
|---|---|---|---|
| T1566.002 | Phishing: Spearphishing Link | high | Prompts users to download an archive and VBScript from a malicious link. |
| T1053.005 | Scheduled Task/Job: Scheduled Task | high | Uses scheduled tasks for the persistence of MATCHBOIL and its payloads. |
| T1497.001 | Virtualization/Sandbox Evasion: System Checks | high | Checks system uptime recorded in Windows event logs and OS installation dates. |
| T1071.001 | Application Layer Protocol: Web Protocols | high | Performs C2 communications and payload retrieval via HTTPS. |
14. Unknowns and Additional Investigations
- Initial emails, compromise durations, acquired data, and the full scope of subsequent payloads for each victim enterprise.
- Individual cases where access was handed off from MATCHBOIL to Sandworm.
- New variants and C2 infrastructure emerging after April 2026.
15. Impact on SOCs and Organizations
Although direct observations are limited to Ukraine, organizations in logistics, manufacturing, energy, and related sectors should remain vigilant against Ukraine-themed spearphishing, VBScript files, and fake utility GUIs. Security operations centers can correlate the hex payloads inside HTML responses and the two-minute C2 intervals across both proxy and endpoint telemetry.
16. Summary by Target Audience
- For SOCs: Correlate archives -> VBScript -> MATCHBOIL -> 3 HTTPS requests -> MATCHWOK -> scheduled tasks.
- For Administrators: Implement script execution controls, email URL defenses, PowerShell/WSH restrictions, and egress monitoring.
- For Users: Do not execute scripts within archives or suspicious planner/text search utilities, and report any occurrences.
Top comments (1)
Some comments may only be visible to logged-in visitors. Sign in to view all comments.