hacker-news · Crawled Jul 31, 2026

HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm

8 IoCs
Read original article ↗

AI Summary

A spear-phishing attack targeting a law firm delivered a multi-stage malware chain involving a Go-based loader framework called HollowFrame and a Rust-based backdoor named Matryoshka. The attack begins with a malicious LNK file disguised as 'Case Documents' that triggers PowerShell to download further payloads. HollowFrame uses DLL side-loading with python.exe and python311.dll to establish persistence via a scheduled task and deploy Matryoshka, which communicates either over HTTP or through a private GitHub repository for command-and-control. Matryoshka variants enable remote command execution, Active Directory reconnaissance, file transfer, and deployment of additional tools, allowing for credential theft and lateral movement.

AI-extracted · verify before operational use

Indicators of Compromise 8 extracted

Type Value Detail
IP 2[.]26[.]252[.]84 Details →
IP 45[.]158[.]196[.]184 Details →
Domain adioziaete/memio Details →
Filename python311.dll Details →
Filename version.dll Details →
Filename wtsapi32.dll Details →
GitHub Repo adioziaete/memio Details →
GitHub User adioziaete Details →