MATCHBOIL, a C# malware downloader linked to UAC-0099, uses command-and-control (C2) servers hidden behind Cloudflare to deliver backdoor payloads.
Its changing code shows how the group has moved from a simple downloader toward repeated server contact, stronger code hiding, and checks designed to stop security researchers from studying infections.
The observed victims were all in Ukraine. ESET recorded infections at transportation companies during July and August 2025, a manufacturing company in December 2025, and an energy company in June 2026.
These findings show continued targeting across sectors, although they do not establish the full scale of the campaign. Researchers from WeLiveSecurity documented these changes in an October 8 research report.
Their review covered samples dating from April 2024 to April 2026. CERT-UA first publicly documented MATCHBOIL in August 2025, but build timestamps suggest development began earlier. ESET assesses UAC-0099’s alignment with Russian interests with medium confidence.
MATCHBOIL Malware Uses Cloudflare-Hidden C2 Servers
The infection begins with links in targeted phishing emails. Victims download an archive containing VBScript and must manually run the script before it downloads and launches MATCHBOIL.
Earlier reporting on UAC-0099 HTA malware delivery described related attacks using fake court notices, giving readers context for the group’s document-based tricks.
Once running, MATCHBOIL checks whether its installation directory already exists and can stop to avoid repeating an installation. It gathers device details through Windows Management Instrumentation, including processor identifiers and BIOS serial numbers.
Later versions collect additional information, such as network addresses and computer details, to identify victims during server contact.
The downloader then makes three HTTPS requests. The first receives a number, which is included in a header during the second request. Researchers believe this number may select a payload or help validate the request, but its exact purpose remains uncertain.
The second response contains HTML with a payload encoded as hexadecimal text. MATCHBOIL extracts that text using a regular expression, converts it into bytes, and writes the payload to disk.
In most cases, ESET identified the downloaded malware as MATCHWOK, a C# backdoor used by UAC-0099. The third request retrieves text that may serve as its configuration.
Cloudflare Concealment and Stronger Evasion
UAC-0099 hosts C2 servers on virtual private servers, including BitLaunch infrastructure, and uses Cloudflare to hide some servers.
ESET also observed Let’s Encrypt certificates that were not reused across domains. Similar MuddyWater cloud proxy abuse shows that hiding server addresses behind commercial services is not unique to this group.
Late-2025 versions replaced earlier Unicode-based code hiding and custom string encryption with Eziriz .NET Reactor. They also checked for debuggers and examined Windows event ID 6013 for at least three records showing two hours of system uptime.
These checks help the malware distinguish ordinary computers from analysis environments. After passing its checks, MATCHBOIL contacts C2 every two minutes instead of operating only once.
.webp)
This allows later attempts if a download fails and lets operators provide newer payloads. Fake planner and text-search windows also distract users when the malware runs without expected arguments.
An April 2026 variant, named MATCHBOIL.V2 by CERT-UA, runs as a DLL through a custom C# loader. Related Notepad++ plugin malware attacks later showed another delivery route for the updated family, while scheduled tasks remained important for maintaining access.
The updated DLL places its downloaded executable in a folder named for an SMTP client and creates a mail-themed scheduled task. This change replaces more noticeable animal-themed filenames, showing how the operators now use names that look closer to normal software.
For defenders, these changes make behavior important alongside file hashes. Teams can investigate unexpected VBScript execution, repeated HTTPS connections from unfamiliar C# programs, and newly created scheduled tasks.
Matching those events with the reported paths and network indicators offers a stronger basis for investigation than treating all Cloudflare traffic as suspicious or relying on a filename alone on affected systems.
Indicators of compromise (IoCs):-
| Filename | SHA-1 |
|---|---|
| PlannerLibrary.dll | B6569B0050B864C4A0D32326954BC2D3852A3958 |
| AnimalUpdater.exe | A926889BAB31F3C34663D18C05C4E862EF367028 |
| bootloader.exe | 026F892630D0A4FE854A75984695BA99AF0022C4 |
| PlannerAssistantManager.exe | F886B615CB9E23EAD2718FF2A61155ACFB04CE9E |
| PlannerAssistantManager.exe | 1E2C4AAC30EDFF86CD9A30BD08B199BCD3D0CCCE |
| RegularExpressionExplorer.exe | C85D28F7D272CE2BBBFB9DAE71D21BF25B8D00FC |
| HelpersLibraries.dll | 6D72B56B86FD5ED9BD188C8C88CFC69476F836E7 |
| April-2026 DLL; filename unspecified | 050926727CDD74F0B3A8A098E60B76D10FB06B14 |
| C2 domain | IP address | First seen |
|---|---|---|
virtualdailyplanner[.]pro | Not listed | 2025-11-10 |
telemetry-conf[.]com | Not listed | 2025-08-12 |
flycloud-service[.]com | 64.95.10[.]223 | 2026-03-03 |
airarticlegenerate[.]com | 64.95.13[.]210 | 2025-05-07 |
| Type | Host indicators |
|---|---|
| Directories | %LOCALAPPDATA%DeviceMonitor; %LOCALAPPDATA%MeowCheck; %LOCALAPPDATA%SMTPClient |
| Payload filenames | MeowMeowProgramm.exe; SMTPClientApplication.exe; Thumbs.db |
| Supporting files | AdditionalLib.dll; config.ini; C:Users; C:UsersPublicLibrariesconfig.library-ms |
| Mutex | GlobalPlannerAssistant |
| Scheduled tasks | UpdatesCheckTask; UpdateCheckersDailyPlanner; MailClientChecker |
| Registry value | DeviceMonitor under HKCUSoftwareMicrosoftWindowsCurrentVersionRun |
| Launch arguments | -auto; -plans; -renew |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC

