Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
MATCHBOIL Deploys Backdoor via Hidden Servers

MATCHBOIL Deploys Backdoor via Hidden Servers

Posted on October 9, 2026 By CWS

MATCHBOIL, a sophisticated malware downloader developed in C#, has been linked to the UAC-0099 group. It utilizes command-and-control (C2) servers obscured by Cloudflare services to introduce backdoor payloads into targeted systems. This evolution reflects a shift from a simple downloader to a more complex tool designed to evade detection through frequent server communications and advanced obfuscation techniques.

Targeted Attacks in Ukraine

Victims of MATCHBOIL have predominantly been identified within Ukraine, affecting sectors such as transportation, manufacturing, and energy. ESET documented these intrusions from July 2025 to June 2026. The research indicates a persistent threat across various industries, although the complete extent of the campaign remains undetermined. A detailed analysis by WeLiveSecurity, published on October 8, outlines the malware’s progression from April 2024 through April 2026.

MATCHBOIL was first publicly noted by CERT-UA in August 2025, but evidence suggests its development may have started earlier. ESET’s investigation aligns UAC-0099’s motives with Russian interests, albeit with medium confidence.

Phishing and Execution Tactics

The infection process begins with targeted phishing emails containing links to a downloadable archive with a VBScript file. Users must manually execute this script, which then downloads and initiates MATCHBOIL. This method traces back to older techniques involving deceptive court notices, providing a historical context for UAC-0099’s document-based strategies.

Upon execution, MATCHBOIL checks for its existence to avoid redundant installations. It collects comprehensive system details including hardware identifiers and network information, aiding in unique victim identification during server interactions.

Concealment and Evasion Strategies

UAC-0099 employs virtual private servers and Cloudflare to conceal C2 server locations. ESET discovered the use of unique Let’s Encrypt certificates across domains, paralleling techniques seen in other cyber operations like MuddyWater. This concealment complicates detection by security practitioners.

Recent updates to MATCHBOIL have replaced simpler encryption with Eziriz .NET Reactor and introduced checks for analysis tools and system uptime. These improvements help avoid detection in research environments. Furthermore, the malware now initiates C2 communication every two minutes, allowing for continuous updates and retries in case of failures.

In April 2026, a variant labeled MATCHBOIL.V2 emerged, operating as a DLL via a custom loader. This version uses more inconspicuous file and task names to blend in with legitimate software, complicating its identification.

For security teams, it is crucial to focus on behavioral indicators such as unexpected VBScript activity and unusual HTTPS traffic from unfamiliar C# applications. These patterns, combined with known file paths and network indicators, provide a stronger investigative foundation than generic traffic analysis.

Cyber Security News Tags:Backdoor, C2 servers, CERT-UA, Cloudflare, Cybersecurity, ESET, evasion tactics, Let's Encrypt, Malware, MATCHBOIL, MATCHWOK, Phishing, UAC-0099, Ukraine

Post navigation

Previous Post: AhsayCBS Flaws Actively Exploited, Urgent Action Needed
Next Post: AI Ambitions Clash with Outdated Security Measures

Related Posts

Threat Actor’s Using Copyright Takedown Claims to Deploy Malware Threat Actor’s Using Copyright Takedown Claims to Deploy Malware Cyber Security News
What Are The Takeaways from The Scattered Lapsus $Hunters Statement? What Are The Takeaways from The Scattered Lapsus $Hunters Statement? Cyber Security News
Insignary Unveils Clarity AIR for Code Security Insignary Unveils Clarity AIR for Code Security Cyber Security News
Cybercriminals Exploit AI to Distribute macOS Malware Cybercriminals Exploit AI to Distribute macOS Malware Cyber Security News
Vietnam Cybercrime Network Fuels Global Account Fraud Vietnam Cybercrime Network Fuels Global Account Fraud Cyber Security News
WhatsApp Denies Lawsuit Claim and Confirms Messages are Device-encrypted and Private WhatsApp Denies Lawsuit Claim and Confirms Messages are Device-encrypted and Private Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • New Exploit in Telegram Desktop Allows Account Takeover
  • AI Involvement in South Korean Bank Hacks Raises Concerns
  • AI Ambitions Clash with Outdated Security Measures
  • MATCHBOIL Deploys Backdoor via Hidden Servers
  • AhsayCBS Flaws Actively Exploited, Urgent Action Needed

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • New Exploit in Telegram Desktop Allows Account Takeover
  • AI Involvement in South Korean Bank Hacks Raises Concerns
  • AI Ambitions Clash with Outdated Security Measures
  • MATCHBOIL Deploys Backdoor via Hidden Servers
  • AhsayCBS Flaws Actively Exploited, Urgent Action Needed

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark