{"id":2143,"date":"2026-07-31T18:12:11","date_gmt":"2026-07-31T18:12:11","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=2143"},"modified":"2026-07-31T18:12:11","modified_gmt":"2026-07-31T18:12:11","slug":"hollowframe-loader-deploys-matryoshka-backdoor-in-spear-phishing-attack-on-law-firm","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=2143","title":{"rendered":"HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Jul 31, 2026<\/span><\/span><span class=\"p-tags\">Endpoint Security \/ Malware<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgjOaqDYzKWLfOEp56DfMjSmDMudw7Y3DBFUY_xOhGNTnzRYlKw9YCNNbjLvepf-vDHB_KVSSA-KZjx2dNXjJR3ZpTpS_IgGSfhLRjyR2P8ocr_uWQ1w5UcYpuXnycnyv2tPtDqXoZMvD9pqgCNCPDrYMwAup0ftaycFLYzxHvdoOWhEA1ZXffc9ahBpkj5\/s1700-e365\/law-firm.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Cybersecurity researchers have shed light on a previously undocumented Go-based loader framework called <strong>HollowFrame<\/strong> and a Rust-based malware family tracked as <strong>Matryoshka<\/strong>.<\/p>\n<p>According to Blackpoint Cyber, the intrusion sequence begins with a spear-phishing message containing a link to an encrypted archive, which holds a Windows Shortcut (LNK). Executing the file triggers a multi-stage chain that involves privilege escalation, weakening Microsoft Defender protections, and downloading additional payloads.<\/p>\n<p>While HollowFrame is launched via a DLL side-loading pair comprising the legitimate Python binary (\u00abpython.exe\u00bb) and a rogue DLL (\u00abpython311.dll\u00bb), Matryoshka comes in two variants, one which supports HTTP-based communication and command execution, and another that uses GitHub for command-and-control (C2), including beaconing, tasking, reconnaissance, file transfer, and secondary payload delivery.<\/p>\n<p>\u00abTogether, HollowFrame and Matryoshka gave the actor a persistent foothold for remote command execution, Active Directory reconnaissance, file transfer, and deployment of follow-on tooling,\u00bb security researchers Nevan Beal and Sam Decker <a href=\"https:\/\/blackpointcyber.com\/blog\/hollowframes-layered-loader-and-matryoshka-backdoors\/\" target=\"_blank\">said<\/a>. \u00abThese capabilities could support credential theft, lateral movement, and broader domain compromise through additional tools delivered after initial access.\u00bb<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-vuln-protection-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjQl2axNwsfhbXOFynrg_uAZsvHi3OvNGSA8KJO-BKR8Xm3x7yjKV3EvfY4v5mwXx6LF0uWFb9h9d9iAV_Pi-YYhqimX9wx4OaLdDJEdR215Xrxq_PAtXkaLfQso4pTSjbj6fvh_ZTliLpzWZSZfcoZgyXtKwhN-SSDDlmbtUqGLshc0KqYQGWYHMN52Sl1\/s728-e100\/zz-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>The cybersecurity company said the multi-stage intrusion targeted two endpoints at an unspecified law firm, with the LNK file masquerading as \u00abCase Documents\u00bb to trick the recipient into clicking it and activating a command sequence that employs PowerShell to fetch next-stage components from a remote server (\u00ab2.26.252[.]84\u00bb).<\/p>\n<p><a name=\"more\"\/><\/p>\n<p>HollowFrame operates as a modular loader and persistence framework that supports various methods to load auxiliary components, at the same time performing anti-analysis checks to avoid running within sandboxed environments. This is determined based on system uptime, installed memory, file count in the user profile, and cursor movement. Persistence is achieved by setting up a scheduled task.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhEQz5wx5Wk3F3uCiiNzfwmlWu3vgQN2TohgoaIdhGjyVcu05SfUmZjzmClUPOkK9M6-S06GZJ4jDqesb_2AYetLTuebp9_K8-Dkfp88cjAJYrzNhyPBwTJ_CD1gWAGuo0cnEz7Mx8eb1r0A5_gv6xsACyEPByhr-COEjfyVn1lIBEJNHK44Vfk7EHCtmHK\/s1700-e365\/cmd.png\" style=\"display: block;  text-align: center; clear: left; float: left;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhEQz5wx5Wk3F3uCiiNzfwmlWu3vgQN2TohgoaIdhGjyVcu05SfUmZjzmClUPOkK9M6-S06GZJ4jDqesb_2AYetLTuebp9_K8-Dkfp88cjAJYrzNhyPBwTJ_CD1gWAGuo0cnEz7Mx8eb1r0A5_gv6xsACyEPByhr-COEjfyVn1lIBEJNHK44Vfk7EHCtmHK\/s1700-e365\/cmd.png\" alt=\"\" border=\"0\" data-original-height=\"588\" data-original-width=\"1008\"\/><\/a><\/div>\n<p>The Go loader comes embedded with an encrypted container, which is then unpacked to launch a second side-loading chain to deploy Matryoshka (\u00abversion.dll\u00bb), a Rust-based backdoor that communicates with its C2 server (\u00ab45.158.196[.]184:8888\u00bb) over HTTP to spawn a shell and deliver additional tooling.<\/p>\n<p>A second DLL (\u00abwtsapi32.dll\u00bb) recovered in connection with the same activity has been flagged as a variant of Matryoshka that makes use of a private GitHub repository (\u00ab<a href=\"https:\/\/github.com\/adioziaete\" target=\"_blank\">adioziaete<\/a>\/memio\u00bb) to poll victim-specific commands, submit results, and fetch payloads.<\/p>\n<p>\u00abThe repository functioned as a collection of per-host mailboxes, with each victim assigned a dedicated <computer>_<username> directory,\u00bb Blackpoint explained. \u00abThese directories contained beacon.json, cmd.json, result.json, and, in some cases, an upload\/ tree for file delivery.\u00bb<\/username><\/computer><\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thn.news\/sygnia-webinar\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhleDdO_4O9-8Pkmidym8Pi9yV4V4jI_M5U0iNRDuoW5Jz3pq7DskZI9OqIChqmY1soaW1ppsC8VLeO55vxSh1m5Q8MJ9ZHuEOSNO5q7K-LwrF6IxrRfCIJOFyoBGaLXGZpkSo8tDirSz-9LmmoOs31tQTlvJWBMLiWJKqMFFaiMmNLV3l-p8zXaFm1VmGG\/s728-e100\/sygnia-d-2.png\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>\u00abThis structure allowed the operator to manage tasking and results for individual endpoints through GitHub without maintaining a custom command server, while also leaving a versioned history of repository changes unless the associated commits or repository were removed.\u00bb<\/p>\n<p>Querying the GitHub API with the username <a href=\"https:\/\/api.github.com\/users\/adioziaete\" target=\"_blank\">shows<\/a> that the account was created on January 6, 2023, and that the profile information was updated as recently as June 7, 2026. It&#8217;s currently not known who is behind the activity.<\/p>\n<p>\u00abAcross the chain, each stage reduced the amount of malicious behavior visible in the stage before it,\u00bb Blackpoint noted. \u00abThat separation complicated attribution and detection because no single component contained the full infection logic or complete C2 picture.\u00bb<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Jul 31, 2026Endpoint Security \/ Malware Cybersecurity researchers have shed light on a previously undocumented Go-based loader framework called HollowFrame and a Rust-based malware family tracked as Matryoshka. According&hellip;<\/p>\n","protected":false},"author":1,"featured_media":2144,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[220,179,297,535,2836,1172,449,2837,947],"class_list":["post-2143","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-attack","tag-backdoor","tag-deploys","tag-firm","tag-hollowframe","tag-law","tag-loader","tag-matryoshka","tag-spearphishing"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2143","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2143"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2143\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/2144"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2143"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2143"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2143"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}