MATCHWOK
MATCHWOK is a C# backdoor used in UAC-0099 phishing-driven cyberespionage campaigns targeting Ukrainian state authorities, the Defense Forces, and defense-industrial enterprises. It is typically deployed as a follow-on payload by the MATCHBOIL loader after initial compromise via phishing emails, often themed as court summons and sent via UKR.NET, with links to legitimate file-hosting services containing a double archive and HTA-based execution chain. MATCHWOK enables remote command execution by executing PowerShell commands, including by compiling .NET programs at runtime and passing commands to the PowerShell interpreter via STDIN. It exfiltrates command output to a remote server over HTTPS, reading the server address from a local configuration file. CERT-UA reporting also states that commands may be AES-256-encrypted and hidden in <script> tags on remote pages. The malware includes anti-analysis behavior and may terminate or avoid execution if tools such as IDA, Wireshark, or Procmon are detected. It has been reported alongside DRAGSTARE, a stealer, as part of the updated UAC-0099 toolkit. High-confidence associations in the provided content link MATCHWOK to persistent espionage activity against Ukrainian government, military, and defense-sector targets since at least 2025, with broader reporting noting UAC-0099 activity against Ukraine since mid-2022.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Techniques & procedures
5 distinct techniques documented for this family, organized by ATT&CK tactic.
Recent activity
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware family delivered via HTA-based phishing lures in campaigns attributed to UAC-0099 (per summary).
Referenced as part of the updated toolset of UAC-0099.
A backdoor deployed by UAC-0099 via the MatchBoil loader, used to maintain persistent access to compromised systems.
A backdoor deployed by UAC-0099 via the MatchBoil loader, used to maintain persistent access to compromised systems.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.