Back Scworld New HollowFrame loader and Matryoshka malware family discovered | brief
A new Go-based loader framework named HollowFrame and a Rust-based malware family called Matryoshka have been identified by cybersecurity researchers at Blackpoint Cyber. These tools were used in a sophisticated attack targeting a law firm, demonstrating advanced techniques for initial access and persistence, based on information published by The Hacker News.
The attack chain begins with a spear-phishing email containing a link to an encrypted archive. This archive holds a Windows Shortcut (LNK) file that, when executed, initiates a multi-stage process. This process includes privilege escalation, disabling Microsoft Defender protections, and downloading further payloads. HollowFrame, the loader, uses a DLL side-loading technique with the legitimate Python binary. It also incorporates anti-analysis checks based on system uptime, memory, file count, and cursor movement to evade sandboxed environments. Persistence is achieved through scheduled tasks.
The Matryoshka backdoor, written in Rust, has two variants: one using HTTP for command and control (C2), and another leveraging a private GitHub repository for C2 communication, tasking, reconnaissance, and file transfer. This modular approach, with each stage obscuring the one, complicates detection and attribution, making it difficult to identify the full infection logic or the complete C2 infrastructure.
Source: The Hacker News
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
