MATCHBOIL.V2 is an upgraded variant of the MATCHBOIL malware family, a C#-based loader associated with the Russia-aligned UAC-0099 threat cluster and used in campaigns targeting Ukrainian organizations. It functions as a follow-on payload in a multi-stage intrusion chain in which a phishing lure leads to execution of a trojanized Notepad++ package, after which intermediary components deploy and launch MATCHBOIL.V2.
The malware’s core role is to fetch and execute additional payloads on compromised Windows systems. Reported functionality includes maintaining persistence through scheduled-task creation, updating its configuration including command-and-control addressing, and downloading further malicious components for subsequent execution. A noted evolution in this version is the use of WinRAR to unpack downloaded objects, with the ability to obtain WinRAR if it is not already present on the host.
In observed operations, MATCHBOIL.V2 was loaded by the BURNYBEAR utility after earlier-stage deployment by the LUNCHPOKE component embedded as a malicious Notepad++ plugin. This places MATCHBOIL.V2 in a broader modular toolchain previously linked to UAC-0099 activity alongside malware such as MATCHWOK and DRAGSTARE. The malware is therefore best characterized as a loader used for post-compromise payload delivery, persistence maintenance, and configuration refresh within targeted espionage-oriented intrusion activity against Ukrainian entities.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
That DLL is a modified version of MATCHBOIL, a C#-based loader capable of fetching and running additional payloads, now designated MATCHBOIL.V2.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
The latest set of attacks begins, observed earlier this summer, with a phishing email containing an image attachment, which, when clicked, opens a URL that's concealed using a link shortener from where the request is sent to a file-sharing service like EasySend[.]co to retrieve a ZIP archive.
It registers a scheduled task under a randomized name to relaunch RemoteLibUpdater.exe every three minutes with the arguments 'setup nodisplay.'
У згаданому архіві міститься VBS-скрипт... у разі запуску скрипт забезпечить завантаження файлу-приманки...
46 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An updated C#-based loader variant capable of retrieving and executing additional payloads as part of UAC-0099's evolving toolchain.
Upgraded loader/backdoor that maintains persistence, updates C2 configuration, and downloads additional payloads. It also uses WinRAR to unpack downloaded components.
Modified version of MATCHBOIL that creates scheduled tasks, updates configuration including C2 address, and downloads additional payloads. The updated variant uses WinRAR to extract downloaded objects and can fetch WinRAR from Dropbox if absent.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.