BREACH WATCH BRIEF High 🔗 Threat intel

Matchboil Downloader Refined by Sandworm‑Linked Group Targets Ukrainian Transport, Energy, Manufacturing

Malware Has Hit Ukrainian Transport, Energy and Manufacturing Firms Eset says Russia-aligned UAC-0099 has spent since at least 2024 refining Matchboil, a downloader used against Ukrainian organizations that now supports recurring command-and-control traffic, stronger evasion and delivery of the Matchwok backdoor.

SeverityHigh
Type🔗 Threat intel
ConfidenceHigh
ReportedOct 8, 2026
Energy & Utilities Transportation operators Energy utilities and grid operators Manufacturing firms with OT/ICS environments Ukrainian organizations using Windows endpoints Malware Other

What happened

A Russian‑aligned cyber‑espionage group (UAC‑0099) has been iteratively improving the Matchboil downloader since 2024. Delivered via spear‑phishing links, the malware contacts a C2 server every two minutes, installs a C# back‑door, and persists through scheduled tasks or registry keys. Variants have been observed in Ukrainian transportation, energy and manufacturing firms.

Why it matters for trust and compliance

  • Check whether the systems or suppliers named here appear in your own inventory.

Who is affected

Transportation operators Energy utilities and grid operators Manufacturing firms with OT/ICS environments Ukrainian organizations using Windows endpoints

Recommended actions

  1. Review and harden email gateway URL‑rewriting or sandboxing for malicious links.
  2. Validate EDR logging of scheduled‑task creation and registry modifications.
  3. Request incident‑response disclosures from any third‑party providers impacted.

Get the Breach Digest

The incidents that matter for your vendors and your data, analysed for practitioners, in one email.