What happened
A Russian‑aligned cyber‑espionage group (UAC‑0099) has been iteratively improving the Matchboil downloader since 2024. Delivered via spear‑phishing links, the malware contacts a C2 server every two minutes, installs a C# back‑door, and persists through scheduled tasks or registry keys. Variants have been observed in Ukrainian transportation, energy and manufacturing firms.
Why it matters for trust and compliance
- Check whether the systems or suppliers named here appear in your own inventory.
Who is affected
Transportation operators Energy utilities and grid operators Manufacturing firms with OT/ICS environments Ukrainian organizations using Windows endpoints
Recommended actions
- Review and harden email gateway URL‑rewriting or sandboxing for malicious links.
- Validate EDR logging of scheduled‑task creation and registry modifications.
- Request incident‑response disclosures from any third‑party providers impacted.