MATCHBOIL.V2 is an updated variant of the MATCHBOIL malware family, a C#-based loader used in campaigns attributed to the Russia-aligned UAC-0099 threat cluster. It has been observed targeting Ukrainian organizations as part of multi-stage intrusion chains that abuse a trojanized Notepad++ plugin delivered through phishing. In these operations, MATCHBOIL.V2 appears as a later-stage payload loaded after intermediary components establish execution and persistence on the victim host.
The malware’s core role is follow-on payload delivery and execution. Reported capabilities include downloading additional malicious components, updating its configuration including command-and-control settings, and creating scheduled tasks for persistence. A notable evolution in this version is the use of WinRAR to unpack downloaded components, with logic to obtain WinRAR if it is not already available on the compromised system. MATCHBOIL.V2 has also been associated with campaigns involving other UAC-0099 tooling, including LUNCHPOKE, BURNYBEAR, MATCHWOK, and DRAGSTARE.
Operationally, MATCHBOIL.V2 is deployed after initial access is achieved through phishing emails that lead victims to execute a disguised script and launch a bundled Notepad++ instance that sideloads a malicious plugin DLL. That plugin chain installs additional components and ultimately loads MATCHBOIL.V2. The malware is therefore best characterized as a Windows loader used for persistence maintenance, configuration management, and staged delivery of further payloads during post-compromise activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The “InitTest.dll” file used during the final stage of the attack is an updated version of the MATCHBOIL malware, tracked as MATCHBOIL.V2. The DLL can create additional scheduled tasks, update command-and-control (C2) configurations, download further malicious payloads and extract downloaded components using WinRAR.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
A scheduled task named \W1n3r-U09oTy-Ap5\Updates is subsequently created on the system. To maintain persistence, the task launches “RemoteLibUpdater.exe” with the setup nodisplay arguments every three minutes.
У згаданому архіві міститься VBS-скрипт... у разі запуску скрипт забезпечить завантаження файлу-приманки...
49 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An updated DLL-based malware used in the final stage of the intrusion. It can create additional scheduled tasks, modify C2 configuration, download further payloads, and extract downloaded components using WinRAR or by downloading WinRAR from Dropbox if absent.
An updated C#-based loader variant capable of retrieving and executing additional payloads as part of UAC-0099's evolving toolchain.
Upgraded loader/backdoor that maintains persistence, updates C2 configuration, and downloads additional payloads. It also uses WinRAR to unpack downloaded components.
Modified version of MATCHBOIL that creates scheduled tasks, updates configuration including C2 address, and downloads additional payloads. The updated variant uses WinRAR to extract downloaded objects and can fetch WinRAR from Dropbox if absent.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.