← Back to Feed
HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm
July 31, 2026 · The Hacker News · Severity: HIGH
Researchers uncovered HollowFrame, a Go-based loader, and Matryoshka, a Rust-based backdoor, used in spear-phishing attacks on a law firm. The attack chain begins with a link to an encrypted archive containing a malicious Windows Shortcut file.
Key Takeaways
- HollowFrame Loader deploys Matryoshka backdoor via spear-phishing.
- Attack starts with encrypted archive link in phishing email.
- Multi-stage chain uses Windows Shortcut to execute malware.