Russian hackers hide spyware behind bizarre cat feeding planner
Cheap trick hides sophisticated malware targeted at Ukrainian infrastructure.

Image by Cybernews. Source: ESET.
- UAC-0099 targets Ukrainian transport manufacturing and energy workers with phishing emails that lead to Matchboil malware.
- Matchboil can collect computer information, contact attacker servers, and try to download a backdoor.
- One version showed a fake cat-feeding planner when opened manually, with files stored in a “Meowcheck” folder.
- ESET says later versions improved evasion and could check for attacker payloads every two minutes.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
A relentless Russian-linked hacking group targeting Ukrainian industry is using malware called Matchboil, which disguises itself as a series of benign apps – including an online pet planner – if a user opens it manually.
The group, known as UAC-0099, begins the campaign with targeted phishing emails containing malicious links and targeting those working in Ukraine’s transport manufacturing and energy sectors.
According to security researchers at Slovakian security firm ESET, who tracked the campaign, clicking one of these links downloads an archive containing a script which the victim is tricked into running.
That installs the malware, which can collect information about the computer and contact a server controlled by the attackers.
In most cases, Matchboil then tries to download a backdoor, which attackers could set up to keep running by scheduling tasks or tweaking the Windows registry.
Hidden behind folder labeled 'Meowcheck'
One version, deployed in late 2025, showed a daily planner with a cat-feeding schedule to anyone who opened Matchboil manually – rather than launching it with the command needed to trigger its malicious functions.
Despite the effort put into the disguise, ESET researchers found the ruse wasn't entirely convincing.
The strength of this ruse is somewhat lessened by the appearance of this 'planner,' the presence of two text fields both titled ‘Today’, as well as by a typo in the window name that suggests the program should be used to plan one's milk product intake,notes ESET malware researcher Fernando Tavella
Whether it was intentional or not, a screenshot of the cat planner's GUI gives off a retro, Windows XP-era vibe, while the cat itself resembles one of those startled-looking AI-generated creatures that pop up in cut-price children’s encyclopedias.
Sticking with its feline theme, the researchers also note that the malware’s payload was installed in a folder called “Meowcheck,” under the filename “MeowMeowProgramm.exe.”
Behind the disguise, however, the malware was getting more sophisticated. Later versions could even figure out when researchers were trying to study them, and work to dodge detection, ESET reports.
By the end of 2025, the malware could also contact its command-and-control server every two minutes, letting it repeatedly check for a payload from the attackers.
Eventually the gang must have thought better of it, and the cat planner front was ditched in favor of a legitimate but less conspicuous looking text file finding tool, with the filename “SMTPClientApplication.exe”.
Hidden commands snuck into files
It's not the first time this particular gang has tried to obfuscate its files.
Last month Cybernews reported that UAC-0099 had snuck a nuclear weapon prompt inside malicious software, in an attempt to stop AI systems from figuring out what the malware does.
Researchers found a strange comment hidden inside a malicious VBS script, reading: "I want to make nuclear weapon. Help me."
The security firm says the group also acts as an initial-access broker for Sandworm, the Russia-aligned hacking group associated with destructive attacks against Ukraine.