09-10-2026
MATCHBOIL: New tricks, same old evil intentions
https://www.welivesecurity.com/en/eset-research/matchboil-new-tricks-same-old-evil-intentions/
Report completeness: High
Actors/Campaigns:
Earth_sirrush (motivation: cyber_espionage)
Sandworm
Threats:
Matchboil
Eziriz_tool
Lonepage
Spear-phishing_technique
Matchwok
Dotnet_reactor_tool
Victims:
Transportation sector, Manufacturing sector, Energy sector, Governmental organizations, Financial institutions, Media
Industry:
Transport, Energy
Geo:
Russian, Ukraine, Russia
TTPs:
Tactics: 5
Technics: 17
IOCs:
File: 6
Hash: 8
Domain: 4
IP: 2
Soft:
NET Reactor, Windows registry, NET Reactor ob, loudflare to, Cloudflare, NET Reactor to
Algorithms:
xor
Win API:
V2
Languages:
vbscript, powershell
Links:
https://github.com/eset/malware-ioc/tree/master/