As cited
Copy frozen at (site build).
HollowFrame Loader Uses Fake Python DLL to Evade Defender
No summary had been written when this copy was frozen.
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
HollowFrame Loader Uses Fake Python DLL to Evade Defender
A new HollowFrame loader evades Windows Defender by embedding Go code within a counterfeit Python dynamic link library (DLL) and pre-staging Defender exclusions to bypass detection. This technique allows the malware to execute malicious payloads while appearing to be legitimate Python functionality.
Why it matters: Security operations and endpoint defense teams should monitor for HollowFrame activity and audit Defender exclusion policies, as adversaries are actively bypassing Windows security features to deliver follow-on payloads.
- Source published
- First seen by Cybersecurity Tracker