WORLDTECH NEWS Global technology intelligence.Contact
← Back to WORLDTECH
Cybersecurity SINGLE SOURCE

Russian-aligned spies upgrade malware used in attacks on Ukrainian transport, energy firms

Padlock and key on a table in front of dark server racksAI illustration
WORLDTECH illustration · AI-generated (Canva)

What happened

In a report on Thursday, ESET said all MatchBoil infections it has observed were in Ukraine. Researchers detected the malware (software written to damage a system or steal from it) at several transportation companies between July and August 2025, at a manufacturing company that December and at an energy-sector company in June 2026.

Russian-aligned hackers have targeted Ukrainian transportation, manufacturing and energy companies with a constantly evolving malware strain designed to harvest system data, according to new research. The malware, known as MatchBoil, is used by UAC-0099, a cyberespionage group that Slovak cybersecurity firm ESET believes is likely working in Russia’s interests.

MatchBoil is typically delivered through malicious links in phishing (messages that impersonate someone to obtain passwords or money) emails. Clicking a link downloads an archive containing files that ultimately execute the malware on the victim’s computer.

MatchBoil can collect information about the infected machine, download additional malicious software from an attacker-controlled server and establish persistence, allowing it to remain on the system. Ukraine’s computer emergency response team, CERT-UA (Center for Cyber Defense and Counterterrorism, Ukraine), first publicly documented MatchBoil in August 2025.

Sources & evidence