VMTech
Discuss a project

HollowFrame loader delivered Matryoshka through a law-firm phishing lure

HollowFrame loader delivered Matryoshka through a law-firm phishing lure

On July 31, 2026, Blackpoint Cyber disclosed a campaign in which the previously undocumented Go-based HollowFrame loader deployed the Rust-based Matryoshka backdoor. The spear-phishing intrusion targeted two endpoints at an unnamed law firm through an encrypted archive containing an LNK file disguised as “Case Documents.”

Why the infection chain is difficult to detect

Opening the shortcut launched PowerShell commands that retrieved further components from 2.26.252[.]84. The chain escalated privileges, weakened Microsoft Defender protections and established persistence before delivering the final backdoor.

The legal-sector lure is significant because case files are routine, time-sensitive attachments. A convincing filename and encrypted archive can therefore bypass both user suspicion and some automated inspection controls.

How HollowFrame and Matryoshka operate

HollowFrame used DLL side-loading with the legitimate python.exe binary and a malicious python311.dll. It checked uptime, installed memory, files in the user profile and cursor movement to identify sandboxes, then created a scheduled task and unpacked an encrypted container.

A second side-loading stage deployed Matryoshka as version.dll. One variant contacted 45.158.196[.]184:8888 over HTTP to open a shell and deliver tools. Another, recovered as wtsapi32.dll, used the private GitHub repository adioziaete/memio for beaconing, commands, results, reconnaissance, file transfer and secondary payloads.

“Together, HollowFrame and Matryoshka gave the actor a persistent foothold for remote command execution, Active Directory reconnaissance, file transfer, and deployment of follow-on tooling.”

Each victim had a dedicated computer_username directory containing files such as beacon.json, cmd.json and result.json. The GitHub account was created on January 6, 2023, and updated as recently as June 7, 2026. The operator remains unknown. The campaign also exemplifies the abuse of borrowed trust in cyberattacks: each stage revealed only part of the infection and C2 logic.

For businesses, the practical response is to inspect encrypted-archive delivery, LNK execution, PowerShell downloads, unusual scheduled tasks and DLL loads by trusted binaries as one correlated sequence. Isolated alerts may look benign; together, they expose the path from phishing to domain-wide compromise.

#cybersecurity#malware#phishing#endpointsecurity#infosec
Open analytics
On the site 0 views
min read 3 31.07.2026
Instagram

HollowFrame loader delivered Matryoshka through a law-firm phishing lure

Open the post on Instagram ↗