MATCHBOIL: New Tricks, Same Old Evil Intentions

    Date: 10/09/2026

    Severity: High

    Summary

    Research documents the evolution of MATCHBOIL, a custom C# downloader used by the Russia-aligned UAC-0099 APT group to deliver payloads and establish persistence on compromised systems. Between 2024 and 2026, the malware evolved with advanced .NET obfuscation, sandbox and anti-analysis checks, and modified persistence mechanisms, including scheduled tasks and registry Run keys. Distributed through spear-phishing emails, MATCHBOIL communicates with C2 servers over HTTPS to retrieve payloads, including the MATCHWOK backdoor, while supporting ongoing cyber espionage operations targeting Ukrainian organizations.

    Indicators of Compromise (IOC) List

    Domains/Urls

    virtualdailyplanner.pro

    telemetry-conf.com

    airarticlegenerate.com

    flycloud-service.com

    IP Address

    64.95.13.210

    64.95.10.223

    Hash

    B6569B0050B864C4A0D32326954BC2D3852A3958

    A926889BAB31F3C34663D18C05C4E862EF367028

    026F892630D0A4FE854A75984695BA99AF0022C4

    F886B615CB9E23EAD2718FF2A61155ACFB04CE9E

    1E2C4AAC30EDFF86CD9A30BD08B199BCD3D0CCCE

    C85D28F7D272CE2BBBFB9DAE71D21BF25B8D00FC

    6D72B56B86FD5ED9BD188C8C88CFC69476F836E7

    Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection       

    Detection Query 1 :

    domainname like "telemetry-conf.com" or url like "telemetry-conf.com" or siteurl like "telemetry-conf.com" or domainname like "flycloud-service.com" or url like "flycloud-service.com" or siteurl like "flycloud-service.com" or domainname like "airarticlegenerate.com" or url like "airarticlegenerate.com" or siteurl like "airarticlegenerate.com" or domainname like "virtualdailyplanner.pro" or url like "virtualdailyplanner.pro" or siteurl like "virtualdailyplanner.pro"

    Detection Query 2 :

    dstipaddress IN ("64.95.13.210","64.95.10.223") or srcipaddress IN ("64.95.13.210","64.95.10.223")

    Detection Query 3 :

    sha1hash IN ("026F892630D0A4FE854A75984695BA99AF0022C4","F886B615CB9E23EAD2718FF2A61155ACFB04CE9E","B6569B0050B864C4A0D32326954BC2D3852A3958","C85D28F7D272CE2BBBFB9DAE71D21BF25B8D00FC","A926889BAB31F3C34663D18C05C4E862EF367028","1E2C4AAC30EDFF86CD9A30BD08B199BCD3D0CCCE","6D72B56B86FD5ED9BD188C8C88CFC69476F836E7"

    Reference:   

    MATCHBOIL                                            


    Tags

    MalwareThreat ActorRussiaAPTObfuscation.NETSpear PhishingBackdoorCyber EspionageUkraine

    « Previous ArticleNext Article »

    Comments

    No records to display

    Looking for Something?
    Threat Research Categories:
    Tags