MATCHBOIL Malware Uses Cloudflare to Hide C2 Servers, Delivers Backdoor Payloads
Key Takeaways The MATCHBOIL C# malware downloader, associated with threat actor UAC-0099, is actively using Cloudflare to mask its command-and-control (C2) infrastructure. The malware targets...
Key Takeaways
- The MATCHBOIL C# malware downloader, associated with threat actor UAC-0099, is actively using Cloudflare to mask its command-and-control (C2) infrastructure.
- The malware targets organizations in Ukraine, with confirmed infections across transportation, manufacturing, and energy sectors.
- MATCHBOIL’s evolution includes enhanced obfuscation techniques, anti-analysis checks, and persistent communication with C2 servers, delivering the MATCHWOK backdoor.
- Defenders should prioritize monitoring for suspicious VBScript execution, unusual C# program network activity, and newly created scheduled tasks.
MATCHBOIL Malware Adapts Evasion Tactics, Leverages Cloudflare for C2 Anonymity
A sophisticated C# malware downloader, dubbed MATCHBOIL, is actively being deployed by the threat group UAC-0099. This malware has evolved to employ advanced evasion techniques, notably utilizing Cloudflare to obscure its command-and-control (C2) servers, thereby complicating detection and analysis efforts. The primary objective of MATCHBOIL is to deliver backdoor payloads, predominantly the MATCHWOK C# backdoor.
Table Of Content
The observed evolution of MATCHBOIL’s codebase signifies a strategic shift by UAC-0099. Initial versions functioned as simple downloaders, but recent iterations demonstrate a move towards sustained server communication, more robust code obfuscation, and integrated checks designed to impede security researchers. Researchers from WeLiveSecurity documented these developments in a comprehensive report published on October 8, analyzing samples from April 2024 through April 2026.
Targeted Operations in Ukraine
Victims identified in this campaign are exclusively located in Ukraine. ESET’s telemetry recorded infections at transportation firms during July and August 2025, a manufacturing entity in December 2025, and an energy company in June 2026. These incidents underscore a persistent, multi-sector targeting strategy by UAC-0099, although the full scope of the campaign remains under investigation. While CERT-UA first publicly detailed MATCHBOIL in August 2025, forensic evidence from build timestamps suggests the malware’s development commenced earlier. ESET assesses with medium confidence that UAC-0099’s activities align with Russian geopolitical interests.
Infection Chain and Malware Functionality
The infection process typically initiates with spear-phishing emails containing malicious links. Should a victim engage with these links, they download an archive that includes a VBScript. Manual execution of this script by the user triggers the download and subsequent launch of the MATCHBOIL malware. Previous reports concerning UAC-0099’s use of HTA malware noted similar document-based deception, often involving fabricated court notices.
Upon execution, MATCHBOIL performs an initial check to determine if its installation directory already exists, preventing redundant installations. It then proceeds to collect system specifics via Windows Management Instrumentation (WMI), including processor identifiers and BIOS serial numbers. Later versions of the malware expand this data collection to include network addresses and more detailed computer information, aiding in victim identification during C2 communications.
The downloader then initiates a series of three HTTPS requests to its C2 server. The first request retrieves a numerical value, which is then incorporated into a header for the second request. Researchers speculate this number might dictate the specific payload to be delivered or serve as a validation token, though its precise function is still being investigated. The second C2 response contains HTML embedded with a payload encoded in hexadecimal. MATCHBOIL employs a regular expression to extract this hexadecimal string, converts it into binary, and writes the resulting payload to disk. In most analyzed cases, ESET identified this downloaded malware as MATCHWOK, a C# backdoor frequently utilized by UAC-0099. The third request is believed to retrieve configuration data for the deployed backdoor.
Cloudflare Concealment and Enhanced Evasion
UAC-0099 hosts its C2 servers on virtual private server infrastructure, including services from BitLaunch. A critical component of their operational security is the use of Cloudflare to obscure the true IP addresses of some C2 servers. ESET has also observed the use of unique Let’s Encrypt certificates for different domains, further enhancing anonymity. This tactic of leveraging commercial services for C2 obfuscation is not unique to UAC-0099, with similar methods observed in campaigns by groups like MuddyWater.
Significant updates to MATCHBOIL in late 2025 introduced advanced evasion techniques. Earlier, simpler Unicode-based code obfuscation and custom string encryption were replaced with Eziriz .NET Reactor. The malware also incorporated checks for debuggers and analyzed Windows event ID 6013 to ensure at least three records indicating two hours of system uptime. These checks are designed to differentiate legitimate user environments from security research sandboxes. If these checks are passed, MATCHBOIL establishes persistent communication with its C2 server, contacting it every two minutes instead of a single interaction. This change allows for potential re-downloads if initial attempts fail and enables operators to push updated payloads. Furthermore, the malware displays deceptive planner and text-search windows to distract users when executed without the expected command-line arguments.
An April 2026 variant, designated MATCHBOIL.V2 by CERT-UA, operates as a DLL loaded by a custom C# loader. Subsequent attacks leveraging malicious Notepad++ plugins revealed another delivery vector for this updated malware family. Scheduled tasks continue to be a crucial mechanism for maintaining persistence. The updated DLL places its downloaded executable in a folder named after an SMTP client and creates a mail-themed scheduled task. This represents a shift from earlier, more conspicuous animal-themed filenames, indicating a move towards naming conventions that mimic legitimate software components.
What You Should Do
- Monitor VBScript Execution: Scrutinize any unexpected execution of VBScript files, especially those originating from email attachments or suspicious downloads.
- Analyze C# Program Network Activity: Investigate repeated HTTPS connections originating from unfamiliar C# programs, particularly if they exhibit unusual data transfer patterns.
- Review Scheduled Tasks: Regularly audit newly created or modified scheduled tasks, looking for entries that correspond to the malware’s known persistence mechanisms (e.g., mail-themed tasks).
- Correlate Indicators: Combine behavioral analysis (VBScript execution, network connections, scheduled tasks) with reported file hashes and network indicators of compromise for a more robust investigation. Relying solely on filenames or generic Cloudflare traffic analysis is insufficient.
- Educate Users: Conduct ongoing security awareness training to educate employees about phishing tactics, the dangers of opening suspicious attachments, and the importance of verifying sender identities.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.