Russian-aligned spies upgrade malware used in attacks on Ukrainian transport, energy firms
Russian-aligned hackers have targeted Ukrainian transportation, manufacturing and energy companies with a constantly evolving malware strain designed to harvest system data, according to new research.
The malware, known as MatchBoil, is used by UAC-0099, a cyberespionage group that Slovak cybersecurity firm ESET believes is likely working in Russia’s interests. In a report on Thursday, ESET said all MatchBoil infections it has observed were in Ukraine.
Researchers detected the malware at several transportation companies between July and August 2025, at a manufacturing company that December and at an energy-sector company in June 2026.
MatchBoil is typically delivered through malicious links in phishing emails. Clicking a link downloads an archive containing files that ultimately execute the malware on the victim’s computer. MatchBoil can collect information about the infected machine, download additional malicious software from an attacker-controlled server and establish persistence, allowing it to remain on the system.
Ukraine’s computer emergency response team, CERT-UA, first publicly documented MatchBoil in August 2025. But ESET said its analysis shows the malware had been under development since at least July 2024, with a newer version appearing as recently as April 2026.
Over that period, the hackers repeatedly modified MatchBoil to make it harder for security software to detect and analyze, improve how it deceives victims and gather more information about infected computers.
The pace of those changes suggests UAC-0099 considers MatchBoil an important part of its arsenal and is continuing to develop it for future operations, ESET researchers said.
“Each new iteration of the downloader was more sophisticated than the last, showing that MatchBoil is an important part of the group’s toolkit,” they added.
Some of the group’s attempts at deception have been less successful.
In one variant discovered in late 2025, the hackers added a fake daily planner that appears if a victim manually opens MatchBoil, apparently to make the program look legitimate. But the planner contains two fields both labeled “Today,” while a typo in its window title makes the application appear to be designed for planning milk consumption.
UAC-0099 has been active since at least 2022 and was first publicly reported by CERT-UA in June 2023. The group has primarily targeted Ukrainian government organizations, financial institutions and media outlets.
Last August, CERT-UA said the group had sent phishing emails disguised as Ukrainian court summonses as part of an espionage campaign targeting government, military and defense organizations.
In that operation, MatchBoil was used to gather information about compromised computers and deploy additional malware, including the MatchWok backdoor, which allows attackers to remotely execute commands, and the Dragstare information stealer, which can extract browser passwords and cookies as well as files stored on a victim’s desktop.
Neither ESET nor CERT-UA has disclosed how many organizations or individuals have been compromised by UAC-0099.
Daryna Antoniuk
is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.



