news.mlab.sh
Back to the feed
malware

MATCHBOIL: New tricks, same old evil intentions

Medium
Summary

ESET researchers have been tracking the evolution of MATCHBOIL, a C# downloader used by the Russia-aligned UAC-0099 APT group since at least 2024. Initially using unprintable Unicode characters for obfuscation and custom encryption, MATCHBOIL has transitioned to utilizing the Eziriz .NET Reactor obfuscator and more sophisticated persistence methods. The group has been targeting various sectors in Ukraine, and the malware is distributed via spearphishing emails. All samples were found in Ukraine.

Read the full article at WeLiveSecurity

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Also covered by 2 other source(s)

Report an error
Confirmed errors are fixed and listed on /corrections.