Technology News

HollowFrame Loader Deploys Matryoshka Backdoor in Spear‑Phishing Attack on Law Firm

New Go‑based loader and Rust‑based backdoor reveal sophisticated multi‑stage attack

Cybersecurity researchers have uncovered a previously undocumented Go‑based loader called HollowFrame and a Rust‑based malware family known as Matryoshka, used in a spear‑phishing campaign targeting a law firm.

Cybersecurity researchers have uncovered a previously undocumented Go‑based loader called HollowFrame and a Rust‑based malware family known as Matryoshka, used in a spear‑phishing campaign targeting a law firm.

The intrusion sequence begins with a spear‑phishing email containing a link to an encrypted archive.

The archive contains a Windows Shortcut (LNK) file that, when executed, initiates the loader.

The loader is written in Go and is previously undocumented; it extracts the backdoor payload and launches it.

The backdoor, written in Rust, is tracked as the Matryoshka family and provides persistent foothold.

In a public statement, Blackpoint Cyber said the multi‑stage chain includes extraction, execution, and persistence mechanisms.

Static analysis reveals that the loader uses obfuscated identifiers and anti‑debugging checks.

Dynamic analysis shows that the backdoor connects to a command‑and‑control server and exfiltrates data from the victim’s machine.

The attack targeted a law firm, exploiting the high‑value nature of legal documents and client data.

Security experts recommend checking for unusual LNK files in encrypted archives and monitoring for Go‑compiled loaders and Rust‑based backdoors.

HollowFrame Loader Deploys Matryoshka Backdoor in Spear‑Phishing Attack on Law Firm

Cybersecurity researchers have uncovered a previously undocumented Go‑ba…

Cybersecurity researchers have uncovered a previously undocumented Go‑ba…

Cybersecurity researchers have uncovered a previously undocumented Go‑based loader called HollowFrame and a Rust‑based malware family known as Matryoshka, used in a spear‑phishing campaign targeting a law firm.

The intrusion sequence begins with a spear‑phishing email containing a link to an encrypted archive.

The archive contains a Windows Shortcut (LNK) file that, when executed,…

The archive contains a Windows Shortcut (LNK) file that, when executed,…

The archive contains a Windows Shortcut (LNK) file that, when executed, initiates the loader.

The loader is written in Go and is previously undocumented; it extracts the backdoor payload and launches it.

The backdoor, written in Rust, is tracked as the Matryoshka family and p…

The backdoor, written in Rust, is tracked as the Matryoshka family and p…

The backdoor, written in Rust, is tracked as the Matryoshka family and provides persistent foothold.

In a public statement, Blackpoint Cyber said the multi‑stage chain includes extraction, execution, and persistence mechanisms.

Static analysis reveals that the loader uses obfuscated identifiers and…

Static analysis reveals that the loader uses obfuscated identifiers and…

Static analysis reveals that the loader uses obfuscated identifiers and anti‑debugging checks.

Dynamic analysis shows that the backdoor connects to a command‑and‑control server and exfiltrates data from the victim’s machine.

The attack targeted a law firm, exploiting the high‑value nature of lega…

The attack targeted a law firm, exploiting the high‑value nature of lega…

The attack targeted a law firm, exploiting the high‑value nature of legal documents and client data.

Security experts recommend checking for unusual LNK files in encrypted archives and monitoring for Go‑compiled loaders and Rust‑based backdoors.