< BACK TO NEWS
importantSYS.SOURCE: The Hacker News2026-07-31T22:09:31+05:30

Advanced Spear-Phishing Attack Utilizes HollowFrame Loader and Matryoshka Backdoor Targeting Law Firm

A targeted spear-phishing attack on a law firm utilized the HollowFrame loader and Matryoshka backdoor, employing a multi-stage chain involving privilege escalation and GitHub-based command-and-control. The attack included anti-analysis measures and persistence mechanisms, enabling remote execution and potential broader domain compromise.

Cybersecurity researchers have shed light on a previously undocumented Go-based loader framework called HollowFrame and a Rust-based malware family tracked as Matryoshka.

According to Blackpoint Cyber, the intrusion sequence begins with a spear-phishing message containing a link to an encrypted archive, which holds a Windows Shortcut (LNK). Executing the file triggers a multi-stage chain that

Read original article

*** END OF TRANSMISSION ***