ESET details evolving MATCHBOIL downloader used in Ukraine espionage campaign

ESET has documented nearly two years of updates to MATCHBOIL, a downloader linked to the Russia-aligned group UAC-0099. The tool is delivered through spear-phishing and installs MATCHWOK, a C# backdoor that can capture screenshots and run PowerShell commands. ESET says all observed victims were in Ukraine, including transportation, manufacturing, and energy organizations.
[paragraphs]
[paragraph] Need ensure no extra. Use plain text. No markdown? It says labeled sections in plain text exactly this format. We can include labels. Good. Need check EXPANDED total under 120. 106. Good. It says 2 short paragraphs. Yes. Potential issue: "commercial .NET obfuscation" source says Eziriz .NET Reactor. We can mention commercial .NET obfuscation. Fine. "sandbox checks based on uptime and OS age" source says reads event logs for uptime, English/Russian, at least three events >=7200 sec; April 2026 OS installed at least ten days. We omitted specifics but okay. "cat-photo planner decoy titled “Dairy.”" source says daily planner with cat photo, window titled Dairy, text boxes Today. Fine. Need maybe include CERT-UA documented Aug 2025 and compilation mid-2024? Not necessary. But "additional factual detail and background" maybe enough. Could include UAC-0099 initial access broker? But summary already. We can include in context. Fine. Need ensure no copying source phrasing. We u