Russian Hackers Enhance MatchBoil Malware for Espionage
· via Dark Reading
A cyber-espionage group, likely linked to Russia, has been refining its MatchBoil malware downloader to target Ukrainian organizations in transportation, manufacturing, and energy sectors. The malware, used to deliver the MatchWok backdoor for persistent system access, has undergone significant upgrades since 2024, including stronger obfuscation, sandbox checks, and evolving persistence mechanisms. The threat actor, UAC-0099, is suspected of working as an initial access broker for the Sandworm group. The malware’s evolution demonstrates a concerted effort to evade detection and enhance its effectiveness in future attacks.
Read the full article
Continue reading at Dark Reading →This is an AI-generated summary. Read the original for the full story.