HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm

Summary

Cybersecurity researchers have uncovered a new Go-based loader framework named HollowFrame, which is used to deploy a Rust-based malware family called Matryoshka. The attack chain starts with a spear-phishing email containing a link to an encrypted archive, leading to the execution of a Windows Shortcut file.

IFF Assessment

FOE

The discovery of a new loader framework and backdoor indicates a new threat that defenders must prepare for.

Defender Context

The emergence of HollowFrame and Matryoshka highlights the evolving tactics used in spear-phishing attacks. Defenders should be vigilant for sophisticated multi-stage infection chains initiated through seemingly innocuous links and encrypted archives, and ensure robust endpoint detection and response capabilities are in place.

Read Full Story →