malware
MATCHBOIL: New tricks, same old evil intentions
Medium
Summary
ESET researchers have been tracking the evolution of MATCHBOIL, a C# downloader used by the Russia-aligned UAC-0099 APT group since at least 2024. Initially using unprintable Unicode characters for obfuscation and custom encryption, MATCHBOIL has transitioned to utilizing the Eziriz .NET Reactor obfuscator and more sophisticated persistence methods. The group has been targeting various sectors in Ukraine, and the malware is distributed via spearphishing emails. All samples were found in Ukraine.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data