HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm
AI Summary
A spear-phishing attack targeting a law firm delivered a multi-stage malware chain involving a Go-based loader framework called HollowFrame and a Rust-based backdoor named Matryoshka. The attack begins with a malicious LNK file disguised as 'Case Documents' that triggers PowerShell to download further payloads. HollowFrame uses DLL side-loading with python.exe and python311.dll to establish persistence via a scheduled task and deploy Matryoshka, which communicates either over HTTP or through a private GitHub repository for command-and-control. Matryoshka variants enable remote command execution, Active Directory reconnaissance, file transfer, and deployment of additional tools, allowing for credential theft and lateral movement.
AI-extracted · verify before operational use