threat-intel
HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm
High
Summary
A previously undocumented Go-based loader framework called HollowFrame and a Rust-based malware family named Matryoshka were used in a spear-phishing attack targeting a law firm. The attack involved a multi-stage process including DLL side-loading, PowerShell execution, and GitHub-based command and control, ultimately enabling remote command execution and broader domain compromise. The attacker utilized a sophisticated approach to obfuscate their activity and evade detection.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
