The report is new; most of the samples are not

On 8 October, ESET published a study of MATCHBOIL, a C# downloader it associates with UAC-0099. The analyzed samples range from April 2024 to April 2026; ESET also reports seeing related telemetry in Ukraine in June 2026. This is a retrospective look at how the tool evolved, not evidence that a fresh campaign began on publication day.

Keep attribution and timing precise

ESET describes UAC-0099 as Russia-aligned with medium confidence, based on targeting. The victims it saw in telemetry were in Ukraine. Do not turn that assessment into a confirmed state attribution or claim that every listed sample is active now.

The same delivery chain can wear different clothes

According to ESET, a spearphishing link leads to an archive containing VBScript; the victim must be persuaded to run the script. The script retrieves MATCHBOIL, which collects basic machine identifiers, contacts command-and-control infrastructure over HTTPS, extracts a hex-encoded payload and installs it with persistence. ESET says that payload was often MATCHWOK, a separate backdoor. MATCHBOIL is the downloader, not the whole intrusion.

Across the samples, the operators changed obfuscation, local filenames, decoy interfaces and persistence. Earlier versions used registry Run entries; later ones used scheduled tasks. By late 2025, ESET saw a timer that could retry command-and-control every two minutes. A 2026 sample used a DLL and a custom loader. A hunt tied only to one filename or task name will miss other variants.

Correlate the stages instead of treating each signal alone

  1. 1

    Start with delivery. Review targeted mail, downloaded archives and script execution on Windows endpoints. Preserve the original lure and archive when an investigation is open.

  2. 2

    Join process and network evidence. Look for VBScript leading to .NET execution, repeated HTTPS requests and subsequent executable or DLL writes under user-writable locations. The exact directory varies by sample.

  3. 3

    Check both persistence paths. Inspect relevant scheduled-task creation and registry Run-key changes, then tie the creator process and timestamp back to the initial script and downloaded file.

  4. 4

    Scope the payload separately. A downloader finding is a starting point. Determine whether a follow-on payload was installed, what it executed and which accounts or systems it reached.

Old indicators are leads, not a date-stamped alert

  • ESET provides sample hashes and infrastructure indicators; use them with the relevant observation windows and current endpoint evidence.
  • A benign-looking planner or search window in these samples is camouflage, not proof the program is legitimate.
  • Low-volume, recurring HTTPS traffic may matter more when joined to a suspicious script, user-profile file write and new scheduled task.

The durable detection opportunity is the sequence: lure, manual script execution, downloader, network retrieval and persistence. ESET's details are valuable because they show where that sequence has stayed recognisable even as the code changed.