Back
Russian Hackers Disguise Matchboil Spyware as Cat-Feeding Planner
SiTech AI Team2 min read

Russian Hackers Disguise Matchboil Spyware as Cat-Feeding Planner

Russian-linked group UAC-0099 is targeting Ukrainian transport, manufacturing, and energy workers with phishing emails that install Matchboil malware, which ESET says hides behind a fake cat-feeding planner.

Russian hackers linked to the group UAC-0099 are targeting workers in Ukraine's transport manufacturing and energy sectors with phishing emails that deliver a malware family called Matchboil, according to researchers at Slovakian security firm ESET. The campaign begins with targeted phishing emails containing malicious links. Clicking a link downloads an archive with a script that victims are tricked into running, which installs the malware on the machine.

Matchboil's capabilities

Once installed, Matchboil can collect information about the infected computer and contact servers controlled by the attackers. In most cases it then attempts to download a backdoor, which the attackers could keep running by scheduling tasks or modifying the Windows registry.

A cat-feeding planner disguise

One version of the malware, deployed in late 2025, displayed a daily planner with a cat-feeding schedule when opened manually, rather than launched with the command needed to trigger its malicious functions. ESET malware researcher Fernando Tavella noted the ruse was not entirely convincing, pointing to two text fields both titled "Today" and a typo in the window name suggesting the program was meant for planning milk product intake. The interface gave off a retro, Windows XP-era vibe, while the cat resembled an AI-generated creature. The malware's payload was installed in a folder called "Meowcheck" under the filename "MeowMeowProgramm.exe."

Improving evasion

Later versions of Matchboil became more sophisticated. ESET reports they could detect when researchers were trying to study them and work to dodge detection. By the end of 2025, the malware could contact its command-and-control server every two minutes, repeatedly checking for a payload from the attackers. Eventually the cat planner front was dropped in favor of a legitimate-looking text file finding tool named "SMTPClientApplication.exe." UAC-0099 has previously tried to obfuscate its files, including hiding a comment reading "I want to make nuclear weapon. Help me." inside a malicious VBS script in an apparent attempt to stop AI systems from analyzing the malware. ESET says the group also acts as an initial-access broker for Sandworm, the Russia-aligned hacking group associated with destructive attacks against Ukraine.

Sources: Cybernews

SSiTech

SiTech — AI-powered web development

We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.