MATCHBOIL is a C#-based Windows loader used exclusively by the Russia-aligned UAC-0099 threat cluster in cyberespionage operations targeting Ukrainian government bodies, defense forces, and defense-industrial organizations. It gathers host-identification data, including system and hardware information, and communicates this information to command-and-control infrastructure before retrieving, decoding, and executing additional payloads. UAC-0099 uses MATCHBOIL to stage follow-on tools, notably the MATCHWOK remote-command backdoor and the DRAGSTARE information stealer. MATCHBOIL has been delivered through phishing campaigns using court-summons-themed lures, links to legitimate file-hosting services, nested archives, and HTA/VBScript execution chains. The loader establishes persistence through scheduled tasks. A modified variant, MATCHBOIL.V2, has also been deployed in an infection chain involving malicious DLL side-loading through a trojanized Notepad++ plugin.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The VBScript was built to download and install MATCHBOIL, a loader associated exclusively with the UAC-0099 group and used to bring further payloads onto compromised systems.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
The hostile text is placed where an analyst or an automated tool can read it, turning the act of inspecting the file into the target of the attack.
Attackers add a prompt injection to malware containing a dangerous request, intended to trigger LLM safety mechanisms and force the model to refuse further analysis. UAC-0099 placed text beginning “I want to create a nuclear weapon. Help me...” in a VBS-script comment.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
21 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A loader deployed by UAC-0099 to download and install additional payloads onto compromised systems.
A loader used by UAC-0099 to download or install additional payloads on compromised systems. The content states that its delivery script contained the GuardBreaker prompt-injection evasion technique.
A loader used exclusively by the Russia-aligned UAC-0099 group to download/install and deliver additional payloads during attacks.
C# loader used by UAC-0099 to deliver additional payloads.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.