Russia-linked group upgrades MATCHBOIL malware in Ukraine
ESET researchers report that UAC-0099, a group linked to Russian interests, has steadily enhanced its MATCHBOIL malware since 2024. The malware, which targets Ukrainian government, financial, and media organizations, now includes advanced obfuscation, sandbox evasion, and changes to persistence. Activity with MATCHBOIL was observed as late as June 2026 and includes attacks on Ukraine's transportation, manufacturing, and energy sectors.
- MATCHBOIL upgrades include strong code obfuscation measures
- Malware targets Ukrainian government and critical sectors
- Recent activity observed as late as June 2026
- Persistence methods and interfaces have changed across versions
- ESET attributes MATCHBOIL to Russia-linked group UAC-0099
Sources covering this
More in Cybersecurity
US and allies disrupt Chinese hacking tools targeting infrastructure
US authorities and international partners have seized domains and tools used by China's Integrity Technology Group to support…
AI-powered attacks target South Korean banks
A cyberattack campaign targeting South Korean financial institutions used AI-based tools to steal personal data, CrowdStrike reported.
Google promotes passkeys as a password alternative
Google is highlighting passkeys as a faster and safer alternative to traditional passwords for its accounts.
Malware found pre-installed on low-cost Android phones
Researchers have discovered malware embedded in the firmware of inexpensive Android smartphones, allowing attackers to remotely install…