MATCHBOIL
MATCHBOIL is a C#-based malware loader used by the threat actor UAC-0099 in phishing-driven cyberespionage campaigns targeting Ukrainian state authorities, the Defense Forces, and defense-industrial enterprises. Recent reporting also describes targeting of government and defense sectors more broadly, and notes UAC-0099 has operated against Ukraine since at least mid-2022. The infection chain commonly begins with phishing emails, often themed as court summons and sent via UKR.NET, containing links to legitimate file-hosting services. These links deliver a double archive with an HTA file; execution of the HTA launches obfuscated VBScript and PowerShell that writes and runs AnimalUpdate.exe, activating MATCHBOIL. MATCHBOIL fingerprints the host by collecting system data including CPU ID, BIOS serial number, username, and MAC address, and uses this information in HTTP headers during C2 communication. It is designed to download and execute additional payloads, including MATCHWOK, a backdoor for remote command execution, and DRAGSTARE, a stealer that extracts browser data such as passwords and cookies, desktop files, screenshots, and other documents. MATCHBOIL retrieves payloads from image-like URIs, decodes them from HEX and BASE64, saves them as .com files, and stores its server address in a local configuration file. Persistence has been reported via a scheduled task named DocumentTask, and separately via creation of a registry Run key to enable execution of downloaded payloads. High-confidence related artifacts from the infection chain include scheduled tasks PdfOpenTask and \AnimalSoft\UpdateAnimalSoftware, files documenttemp.txt, temporarydoc.txt, %PUBLIC%\Downloads\AnimalUpdate.txt, and AnimalUpdate.exe. MATCHBOIL has been described as likely replacing the earlier UAC-0099 malware LONEPAGE.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Techniques & procedures
5 distinct techniques documented for this family, organized by ATT&CK tactic.
Initial Access
2 techniques
Initial Access
Execution
1 technique
Execution
Discovery
1 technique
Discovery
Recent activity
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware family delivered via HTA-based phishing lures in campaigns attributed to UAC-0099 (per summary).
Referenced as part of the updated toolset of UAC-0099.
A next-generation malware loader used by UAC-0099 to download and execute additional malicious payloads, such as backdoors and infostealers.
A next-generation malware loader used by UAC-0099 to download and execute additional malicious payloads, such as backdoors and infostealers.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.