Back to Newsroom
Threat Intel

MATCHBOIL Downloader Hides C2 Traffic Behind Cloudflare to Drop Backdoors

A C# downloader tied to the UAC-0099 threat cluster is routing its command-and-control traffic through Cloudflare and VPS hosting to disguise infections across Ukrainian transport, manufacturing and energy targets.

MATCHBOIL Downloader Hides C2 Traffic Behind Cloudflare to Drop Backdoors

MATCHBOIL Downloader Hides C2 Traffic Behind Cloudflare to Drop Backdoors

A malware downloader tracked as MATCHBOIL is being used by the UAC-0099 threat cluster to quietly stage backdoor infections against organizations in Ukraine, hiding its command-and-control (C2) infrastructure behind Cloudflare and commercial VPS providers to blend in with legitimate web traffic.

What happened

MATCHBOIL is a C# downloader first documented publicly by Ukraine's CERT-UA in August 2025, though build timestamps suggest development started earlier. A review of samples spanning April 2024 to April 2026 shows the tool has matured considerably: what began as a simple one-shot downloader now re-contacts its C2 server every two minutes, hides its code behind commercial obfuscation (Eziriz .NET Reactor), and actively checks for debuggers and short system uptime to avoid running inside analysis environments.

Infections start with phishing emails carrying a link to a malicious archive. Once executed, MATCHBOIL profiles the machine through Windows Management Instrumentation — pulling processor and BIOS identifiers, and in later builds, network details — before reaching out to its C2 over HTTPS in a three-step exchange. The final stage decodes a hex-encoded payload and writes it to disk, most often a C# backdoor identified as MATCHWOK.

To avoid raising suspicion when launched outside its expected delivery chain, MATCHBOIL displays a decoy "daily planner" application, keeping the victim distracted while the real payload installs in the background.

Why it matters

The campaign has hit organizations across several sectors in Ukraine: transportation companies in mid-2025, a manufacturing firm in December 2025, and an energy company as recently as June 2026 — a sign the operators are still actively targeting critical infrastructure. Analysts assess UAC-0099's objectives align with Russian interests, though attribution is held at medium confidence.

The group's reliance on Cloudflare and other commercial hosting to mask its C2 servers mirrors a broader trend among state-linked actors — also observed with groups like MuddyWater — that makes network-layer blocking far less effective than behavior-based detection. A newer variant, MATCHBOIL.V2, now loads as a DLL and disguises its persistence mechanisms as SMTP/mail-client components rather than the earlier animal-themed names, a deliberate move to blend into normal software inventories.

What to do

  • Hunt for unexpected VBScript execution and newly created scheduled tasks rather than relying on file names alone — the group actively renames artifacts to look benign.
  • Flag repeated HTTPS connections from unfamiliar C# binaries, especially at short, regular intervals (roughly every two minutes is a strong behavioral signal for this family).
  • Correlate known file hashes and C2 domains/IPs with internal telemetry instead of blanket-blocking Cloudflare-fronted traffic, which would generate excessive false positives.
  • Treat phishing-delivered archives and HTA/VBScript loaders as a priority detection surface, particularly for organizations in critical infrastructure sectors with ties to the region.
SHARE