What the research says
The report is new; most of the samples are not
On 8 October, ESET published a study of MATCHBOIL, a C# downloader it associates with UAC-0099. The analyzed samples range from April 2024 to April 2026; ESET also reports seeing related telemetry in Ukraine in June 2026. This is a retrospective look at how the tool evolved, not evidence that a fresh campaign began on publication day.
Keep attribution and timing precise
How it works
The same delivery chain can wear different clothes
According to ESET, a spearphishing link leads to an archive containing VBScript; the victim must be persuaded to run the script. The script retrieves MATCHBOIL, which collects basic machine identifiers, contacts command-and-control infrastructure over HTTPS, extracts a hex-encoded payload and installs it with persistence. ESET says that payload was often MATCHWOK, a separate backdoor. MATCHBOIL is the downloader, not the whole intrusion.
Across the samples, the operators changed obfuscation, local filenames, decoy interfaces and persistence. Earlier versions used registry Run entries; later ones used scheduled tasks. By late 2025, ESET saw a timer that could retry command-and-control every two minutes. A 2026 sample used a DLL and a custom loader. A hunt tied only to one filename or task name will miss other variants.
Defender workflow
Correlate the stages instead of treating each signal alone
- 1
Start with delivery. Review targeted mail, downloaded archives and script execution on Windows endpoints. Preserve the original lure and archive when an investigation is open.
- 2
Join process and network evidence. Look for VBScript leading to .NET execution, repeated HTTPS requests and subsequent executable or DLL writes under user-writable locations. The exact directory varies by sample.
- 3
Check both persistence paths. Inspect relevant scheduled-task creation and registry Run-key changes, then tie the creator process and timestamp back to the initial script and downloaded file.
- 4
Scope the payload separately. A downloader finding is a starting point. Determine whether a follow-on payload was installed, what it executed and which accounts or systems it reached.
Defender note
Old indicators are leads, not a date-stamped alert
- ESET provides sample hashes and infrastructure indicators; use them with the relevant observation windows and current endpoint evidence.
- A benign-looking planner or search window in these samples is camouflage, not proof the program is legitimate.
- Low-volume, recurring HTTPS traffic may matter more when joined to a suspicious script, user-profile file write and new scheduled task.
The durable detection opportunity is the sequence: lure, manual script execution, downloader, network retrieval and persistence. ESET's details are valuable because they show where that sequence has stayed recognisable even as the code changed.