MATCHWOK is a C# backdoor associated with the Russia-aligned UAC-0099 threat cluster and used in cyber-espionage operations targeting Ukrainian government bodies, defense forces, and defense-industrial organizations. It is typically deployed as a secondary payload by the MATCHBOIL loader during phishing-led intrusion chains. Reported delivery patterns include court-summons-themed phishing emails and other lure emails that direct victims to archives or trojanized software components, after which MATCHBOIL installs MATCHWOK alongside other tooling such as the DRAGSTARE infostealer.
The malware’s core function is remote command execution. MATCHWOK is designed to execute PowerShell commands on compromised Windows systems, including by compiling .NET code at runtime and passing commands to the PowerShell interpreter through standard input. It then captures execution results and transmits them to attacker-controlled infrastructure. Reported tradecraft also includes receiving encrypted tasking from remote content and using local configuration data to determine command-and-control parameters.
MATCHWOK has been described as part of an evolving UAC-0099 toolkit that supports persistent access and post-compromise operations. In observed campaigns, persistence is primarily established earlier in the infection chain through scheduled tasks created by companion malware such as MATCHBOIL and related loaders. MATCHWOK also incorporates anti-analysis behavior, including checks for common reverse-engineering and monitoring tools, consistent with an espionage-focused backdoor intended to remain undetected while enabling operator-driven activity on victim hosts.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Other cyber attacks mounted by the adversary have employed phishing emails as an initial access method to deploy MATCHBOIL, MATCHWOK, and DRAGSTARE.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware family previously deployed by UAC-0099 via phishing emails.
Previously observed malware associated with earlier UAC-0099 campaigns; mentioned as historical context alongside MATCHBOIL.
Malware family delivered via HTA-based phishing lures in campaigns attributed to UAC-0099 (per summary).
Referenced as part of the updated toolset of UAC-0099.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.