CYBERSECURITYTRACKER
TRACKING6,626 stories in this site build1,366 vulnerability news stories in this site build
Permanent story citation

HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3648

As cited

Copy frozen at (site build).

threat intel

HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm

Researchers discovered HollowFrame, a previously unknown Go-based loader, and Matryoshka, a Rust-based backdoor, deployed together in targeted attacks against law firms. The attack chain starts with spear-phishing emails containing links to encrypted archives with Windows Shortcut files that trigger a multi-stage infection sequence.

Why it matters: Law firms and their employees face targeted compromise through email-based attacks; practitioners should treat spear-phishing with encrypted attachments as high-risk and implement controls to block or detonate such payloads.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm

Researchers discovered HollowFrame, a previously unknown Go-based loader, and Matryoshka, a Rust-based backdoor, deployed together in targeted attacks against law firms. The attack chain starts with spear-phishing emails containing links to encrypted archives with Windows Shortcut files that trigger a multi-stage infection sequence.

Why it matters: Law firms and their employees face targeted compromise through email-based attacks; practitioners should treat spear-phishing with encrypted attachments as high-risk and implement controls to block or detonate such payloads.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary