← Back to Feed

HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm

July 31, 2026 · The Hacker News · Severity: HIGH

Researchers uncovered HollowFrame, a Go-based loader, and Matryoshka, a Rust-based backdoor, used in spear-phishing attacks on a law firm. The attack chain begins with a link to an encrypted archive containing a malicious Windows Shortcut file.

Key Takeaways

  • HollowFrame Loader deploys Matryoshka backdoor via spear-phishing.
  • Attack starts with encrypted archive link in phishing email.
  • Multi-stage chain uses Windows Shortcut to execute malware.
☕ Buy a Coffee