CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

HollowFrame Loader Uses Fake Python DLL to Evade Defender

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6315

As cited

Copy frozen at (site build).

HollowFrame Loader Uses Fake Python DLL to Evade Defender

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

HollowFrame Loader Uses Fake Python DLL to Evade Defender

A new HollowFrame loader evades Windows Defender by embedding Go code within a counterfeit Python dynamic link library (DLL) and pre-staging Defender exclusions to bypass detection. This technique allows the malware to execute malicious payloads while appearing to be legitimate Python functionality.

Why it matters: Security operations and endpoint defense teams should monitor for HollowFrame activity and audit Defender exclusion policies, as adversaries are actively bypassing Windows security features to deliver follow-on payloads.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary