MATCHBOIL.V2 is an updated C#-based Windows loader used by UAC-0099, a threat cluster overlapping with the Russia-aligned espionage group Earth Sirrush. It downloads and executes additional malicious payloads, creates scheduled tasks for persistence, and updates its configuration, including command-and-control server addresses. Compared with earlier MATCHBOIL versions, it incorporates stronger encryption and revised concealment. It uses WinRAR to extract downloaded components and can retrieve the utility from Dropbox when it is absent.
MATCHBOIL.V2 has been deployed in phishing campaigns against Ukrainian organizations. The infection chain uses emailed images linking to hosted archives containing VBScript files disguised as documents through concealed double extensions. Executing the script retrieves a decoy document and a package containing legitimate Notepad++ software with the malicious LUNCHPOKE plugin. Notepad++ loads LUNCHPOKE through its normal plugin mechanism; LUNCHPOKE deploys BURNYBEAR, which loads MATCHBOIL.V2. The loader provides persistent follow-on payload delivery within the broader intrusion.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
UAC-0099 : nouveaux outils LUNCHPOKE, BURNYBEAR et MATCHBOIL.V2 via DLL hijacking Notepad++
LUNCHPOKE deploys BURNYBEAR, a .NET loader, and MATCHBOIL.V2, an updated loader with stronger encryption and revised concealment.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
A scheduled task named \W1n3r-U09oTy-Ap5\Updates is subsequently created on the system. To maintain persistence, the task launches “RemoteLibUpdater.exe” with the setup nodisplay arguments every three minutes.
У згаданому архіві міститься VBS-скрипт... у разі запуску скрипт забезпечить завантаження файлу-приманки...
50 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An updated loader deployed through LUNCHPOKE, featuring stronger encryption and revised concealment techniques.
Updated malware loader deployed by LUNCHPOKE, featuring stronger encryption and revised payload-concealment techniques. The associated chain uses randomized writable directories and renamed Windows scheduling utilities for recurring execution.
An updated DLL-based malware used in the final stage of the intrusion. It can create additional scheduled tasks, modify C2 configuration, download further payloads, and extract downloaded components using WinRAR or by downloading WinRAR from Dropbox if absent.
An updated C#-based loader variant capable of retrieving and executing additional payloads as part of UAC-0099's evolving toolchain.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.