Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
MalwareUsed by 1 actor

MATCHWOK

MATCHWOK is a C# backdoor used in UAC-0099 phishing-driven cyberespionage campaigns targeting Ukrainian state authorities, the Defense Forces, and defense-industrial enterprises. It is typically deployed as a follow-on payload by the MATCHBOIL loader after initial compromise via phishing emails, often themed as court summons and sent via UKR.NET, with links to legitimate file-hosting services containing a double archive and HTA-based execution chain. MATCHWOK enables remote command execution by executing PowerShell commands, including by compiling .NET programs at runtime and passing commands to the PowerShell interpreter via STDIN. It exfiltrates command output to a remote server over HTTPS, reading the server address from a local configuration file. CERT-UA reporting also states that commands may be AES-256-encrypted and hidden in <script> tags on remote pages. The malware includes anti-analysis behavior and may terminate or avoid execution if tools such as IDA, Wireshark, or Procmon are detected. It has been reported alongside DRAGSTARE, a stealer, as part of the updated UAC-0099 toolkit. High-confidence associations in the provided content link MATCHWOK to persistent espionage activity against Ukrainian government, military, and defense-sector targets since at least 2025, with broader reporting noting UAC-0099 activity against Ukraine since mid-2022.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
UAC-0099

04.08.2025 Оновлений інструментарій UAC-0099: MATCHBOIL, MATCHWOK, DRAGSTARE

via cert uacert.gov.ua
MITRE ATT&CK

Techniques & procedures

5 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

2 techniques
T1566PhishingEvidence2

The attacks, which leverage phishing emails as an initial compromise vector, are used to deliver malware families like MATCHBOIL, MATCHWOK, and DRAGSTARE.

T1566.002Spearphishing LinkEvidence1

The latest infection chain involves using email lures related to court summons to entice recipients into clicking on links that are shortened using URL shortening services like Cuttly.

Execution

2 techniques
T1059Command and Scripting InterpreterEvidence1

Matchwok, a backdoor that enables remote command execution

T1204.002Malicious FileEvidence1

...point to a double archive file containing an HTML Application...

Collection

1 technique
T1560Archive Collected DataEvidence1

These links... point to a double archive file containing an HTML Application...

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping5

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.