HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm

HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm
Researchers uncovered HollowFrame, a Go-based loader framework, and Matryoshka, a Rust-based malware family used in a multi-stage intrusion against two endpoints at a law firm. The attack used spear-phishing, DLL side-loading, and GitHub-based command-and-control to enable persistence, reconnaissance, file transfer, and follow-on payload delivery. #HollowFrame #Matryoshka #GitHub #BlackpointCyber

Keypoints

  • The intrusion began with a spear-phishing email containing a link to an encrypted archive.
  • The archive delivered an LNK file disguised as β€œCase Documents” to trigger the attack chain.
  • HollowFrame used DLL side-loading, anti-analysis checks, and scheduled tasks for persistence.
  • Matryoshka appeared in two variants, including one that used GitHub for C2 activity.
  • The malware enabled remote command execution, Active Directory reconnaissance, and payload delivery.

Read More: https://thehackernews.com/2026/07/hollowframe-loader-deploys-matryoshka.html