2 Remove Virus

Russian-linked hackers disguise malware as cat-feeding app in attacks on Ukraine

A Russian-linked cyberespionage group has been using increasingly sophisticated malware to target Ukrainian organizations, including a version disguised as an ordinary application for planning daily activities and feeding a cat.

 

 

The malware, known as MATCHBOIL, is associated with UAC-0099, a hacking group that cybersecurity researchers believe operates in support of Russian interests. According to a new investigation by ESET, the group has continued improving its malicious software to make infections harder to detect.

Researchers identified MATCHBOIL at several Ukrainian transportation companies during July and August 2025, followed by a manufacturing company in December. Another detection occurred at an energy-sector organization in June 2026.

The attacks typically begin with targeted phishing emails containing malicious links. These links lead to archives containing scripts that victims can be tricked into running, allowing MATCHBOIL to install itself on their computers.

Once active, the malware contacts servers controlled by the attackers and attempts to download additional malicious software. This can include backdoors that provide continued access to compromised systems.

One particularly unusual version discovered in late 2025 displayed a fake daily planner when opened manually. The application appeared to offer a schedule for feeding a cat, concealing the program’s actual purpose.

The disguise contained several mistakes, including duplicated fields and an incorrectly named window. Researchers also discovered that the malware stored its additional components in a folder called “Meowcheck,” with an executable named “MeowMeowProgramm.exe.”

Despite the unusual appearance, MATCHBOIL was becoming more dangerous. ESET found that newer versions could communicate with attacker-controlled servers every two minutes, allowing the operators to repeatedly check for additional malicious payloads.

The developers also introduced techniques intended to make security analysis more difficult. These included checks for virtual environments commonly used by malware researchers and stronger methods for hiding the program’s underlying code.

By early 2026, the attackers had replaced the conspicuous cat-themed interface with a more ordinary-looking text-search utility. Later versions also adopted less suspicious filenames and installation locations.

ESET believes MATCHBOIL may have been under development since April 2024, more than a year before Ukrainian authorities publicly documented it.

Researchers assess with medium confidence that UAC-0099 is aligned with Russian interests. The group may also provide initial access to Sandworm, another Russia-aligned hacking operation associated with destructive cyberattacks.

The findings show that MATCHBOIL remains an evolving threat to Ukrainian organizations. However, the research does not establish how many systems were compromised or whether the observed infections caused operational disruptions.