Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
HollowFrame and Matryoshka Backdoor Target Law Firm

HollowFrame and Matryoshka Backdoor Target Law Firm

Posted on July 31, 2026 By CWS

Recent investigations by cybersecurity experts have unveiled a new Go-based loader framework known as HollowFrame, alongside a Rust-based malware family named Matryoshka. These tools have been used in a sophisticated cyber attack targeting a law firm through spear-phishing tactics.

Intrusion Methodology and Initial Attack

Blackpoint Cyber’s report indicates that the attack initiates with a spear-phishing email containing a link to an encrypted archive. This archive includes a Windows Shortcut (LNK) file, which, when executed, initiates a complex sequence of steps. These steps include elevating privileges, disabling Microsoft Defender, and downloading further malicious payloads.

The HollowFrame loader operates through a DLL side-loading technique, involving a legitimate Python executable (‘python.exe’) paired with a malicious DLL (‘python311.dll’). Meanwhile, Matryoshka presents two distinct variants: one utilizing HTTP for command execution and communication, and another leveraging GitHub for command-and-control (C2) operations.

Capabilities and Impact of HollowFrame and Matryoshka

Security analysts Nevan Beal and Sam Decker highlight that the combination of HollowFrame and Matryoshka provides attackers with a sustained remote access capability. This enables remote command execution, reconnaissance of Active Directory environments, and file transfers, facilitating potential credential theft and lateral movement within the victim’s network.

The attack targeted two endpoints at a law firm, with the LNK file disguised as ‘Case Documents’ to deceive recipients. Once activated, a PowerShell script downloads further components from a remote server (‘2.26.252[.]84’). HollowFrame also employs anti-analysis techniques to evade detection, assessing factors like system uptime and cursor movement.

Technical Details and Future Outlook

Embedded within the Go loader is an encrypted container that unpacks to initiate another side-loading chain, deploying the Matryoshka backdoor (‘version.dll’). This backdoor communicates with its C2 server (‘45.158.196[.]184:8888’) over HTTP to deliver additional tools and execute commands.

Another DLL (‘wtsapi32.dll’) identified in the attack functions as a Matryoshka variant using a private GitHub repository (‘adioziaete/memio’) for task management. It stores victim-specific commands and results, allowing attackers to manage individual endpoints without a dedicated command server.

Despite efforts to trace the attackers, their identities remain unknown. The use of separate stages in the attack chain obfuscates malicious activity, complicating detection and attribution. As cybersecurity threats evolve, understanding such sophisticated methods is crucial for enhancing security measures against similar attacks in the future.

The Hacker News Tags:cyber attack, Cybersecurity, DLL side-loading, Go loader, HollowFrame, law firm, Malware, Matryoshka, Rust-based malware, spear-phishing

Post navigation

Previous Post: AI Powers Google Chrome Security with 1,072 Fixes
Next Post: North Korean Cyber Campaign Targets Crypto Wallets

Related Posts

Claude AI Exploited to Operate 100+ Fake Political Personas in Global Influence Campaign Claude AI Exploited to Operate 100+ Fake Political Personas in Global Influence Campaign The Hacker News
Critical Windows Server 2025 dMSA Vulnerability Enables Active Directory Compromise Critical Windows Server 2025 dMSA Vulnerability Enables Active Directory Compromise The Hacker News
Malicious VS Code Extensions Target Crypto Wallets Malicious VS Code Extensions Target Crypto Wallets The Hacker News
Critical Vulnerability in Gogs Allows Remote Code Execution Critical Vulnerability in Gogs Allows Remote Code Execution The Hacker News
Cybersecurity Updates: Qualcomm Flaw and iOS Exploit Chains Cybersecurity Updates: Qualcomm Flaw and iOS Exploit Chains The Hacker News
Chinese DeepSeek-R1 AI Generates Insecure Code When Prompts Mention Tibet or Uyghurs Chinese DeepSeek-R1 AI Generates Insecure Code When Prompts Mention Tibet or Uyghurs The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Linux Kernel Flaw Allows Privilege Escalation
  • New Cyclops Blink Malware Targets Corporate Networks
  • WhatsApp Tests New Feature to Lock Chats on Primary Phone
  • Microsoft’s $30,000 Bounty for AI Vulnerabilities
  • Critical Nintendo Switch Flaw Allows Code Execution

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Linux Kernel Flaw Allows Privilege Escalation
  • New Cyclops Blink Malware Targets Corporate Networks
  • WhatsApp Tests New Feature to Lock Chats on Primary Phone
  • Microsoft’s $30,000 Bounty for AI Vulnerabilities
  • Critical Nintendo Switch Flaw Allows Code Execution

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark