MATCHWOK is a C# backdoor used by UAC-0099 in cyberespionage operations against Ukrainian organizations. It enables remote command execution, including PowerShell commands, and returns execution results to an attacker-controlled server, providing operators with continued access to compromised Windows systems.
MATCHWOK is commonly installed by the MATCHBOIL downloader. The infection chain typically begins with spearphishing emails containing links to archives with malicious VBScript files. When victims manually execute these scripts, they download and launch MATCHBOIL, which retrieves and installs the backdoor and establishes payload persistence through scheduled tasks or Windows registry autostart mechanisms. Campaigns deploying this toolset have targeted Ukrainian transportation, manufacturing, and energy organizations, as well as government, military, and defense entities. MATCHWOK operates alongside other UAC-0099 tools, including the DRAGSTARE information stealer.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
MatchBoil is designed to deliver MatchWok, a C# backdoor that provides persistent access to compromised systems.
This phase introduced MATCHBOIL, MATCHWOK, and DRAGSTARE, reported by CERT-UA.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
27 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
C# backdoor delivered by MatchBoil in UAC-0099's campaign against Ukrainian organizations, providing persistent access to compromised systems.
Backdoor associated with MATCHBOIL in UAC-0099's toolset. It enables remote command execution, supporting further activity on compromised systems.
Backdoor delivered as a payload by MATCHBOIL in UAC-0099 cyberespionage operations targeting Ukrainian organizations. The reference does not describe its specific capabilities or implementation.
A C# backdoor used by UAC-0099 and identified as the payload downloaded by MATCHBOIL in most observed cases. The content does not detail its commands or other capabilities.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.