HollowFrame Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
2
occurrences
First Seen
August 1, 2026
Last Seen
August 3, 2026

HollowFrame is a malware family tracked by ThreatCluster, appearing in 1 threat cluster built from 2 intelligence report mentions.

HollowFrame is a malware family tracked across 1 threat cluster and 2 intelligence report mentions on ThreatCluster. First observed August 1, 2026; most recent activity August 3, 2026.

Related Threat Clusters

Recent Intelligence Reports

  • HollowFrame Loader Uses Fake Python DLL to Evade Defender — Infosecurity-Magazine · August 3, 2026
  • New HollowFrame loader and Matryoshka malware family discovered | brief — Scworld · August 1, 2026

Frequently asked questions

What is HollowFrame?

HollowFrame is a malware family tracked by ThreatCluster, appearing in 1 threat cluster built from 2 intelligence report mentions.

Is HollowFrame still active?

The most recent intelligence report mentioning HollowFrame on ThreatCluster is dated August 3, 2026. Activity was first observed August 1, 2026, giving a tracked span from then to August 3, 2026.

What is HollowFrame associated with?

Across ThreatCluster reporting, HollowFrame most frequently co-occurs with Malware, Phishing, Matryoshka, T1047 - Windows Management Instrumentation, T1053 - Scheduled Task/Job, among 12 tracked related entities.

What are the latest developments involving HollowFrame?

The most significant recent cluster is “HollowFrame Loader and Matryoshka Malware Target Law Firm with Advanced Techniques” (2 articles · Updated August 3, 2026). HollowFrame appears across 1 threat cluster in total, listed above with sources.

How much reporting does ThreatCluster have on HollowFrame?

HollowFrame appears in 2 intelligence report mentions across 1 deduplicated threat cluster, aggregated from 17,000+ monitored sources.

CVSS v3.1 Breakdown