MATCHBOIL is a C#-based Windows malware loader used in cyberespionage campaigns attributed to the Russia-aligned threat cluster UAC-0099. It has been deployed against Ukrainian state authorities, defense forces, and defense-industrial organizations, and appears to have supplanted LONEPAGE in more recent UAC-0099 operations. A modified variant referred to as MATCHBOIL.V2 has also been observed in a Notepad++ plugin-based intrusion chain, where it is loaded by an intermediate component and used to deliver secondary payloads.
Its core role is to fingerprint compromised hosts, retrieve additional malicious components, and ensure their execution. Reported host profiling includes collection of system identifiers such as CPU and BIOS information, username, and MAC address, which are used during command-and-control communications. MATCHBOIL downloads follow-on payloads, including the MATCHWOK backdoor and the DRAGSTARE infostealer, and decodes staged content before writing executable components to disk. Persistence has been observed through scheduled tasks and, in some reporting, Run-key execution mechanisms associated with launched payloads.
Observed delivery chains rely primarily on phishing. UAC-0099 has used court-summons-themed emails and links to legitimate file-hosting services that deliver archives containing HTA and VBScript stages, ultimately leading to MATCHBOIL execution. In a separate chain, a malicious Notepad++ plugin was used to unpack and launch components that loaded MATCHBOIL.V2. Across these campaigns, MATCHBOIL functions as the enabling loader for broader post-compromise activity, supporting follow-on remote command execution, credential and browser-data theft, and document collection through secondary malware.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The "RemoteLibUpdater.exe" binary is BURNYBEAR, which serves as a loader for "InitTest.dll," a modified version of MATCHBOIL, a C#-based loader capable of delivering secondary payloads. The new version has been codenamed MATCHBOIL.V2.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A C#-based loader capable of delivering secondary payloads; in this campaign a modified version is used as InitTest.dll and referred to as MATCHBOIL.V2.
Malware family delivered via HTA-based phishing lures in campaigns attributed to UAC-0099 (per summary).
Referenced as part of the updated toolset of UAC-0099.
A next-generation malware loader used by UAC-0099 to download and execute additional malicious payloads, such as backdoors and infostealers.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.