LIVE · cybersecurity feed
Live wire

go

malwarehigh

HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm

Cybersecurity researchers have identified a new Go-based loader framework named HollowFrame, which is used in conjunction with a Rust-based backdoor called Matryoshka. The attack chain begins with a spear-phishing email containing a malicious link that, when clicked, leads to the execution of a Windows Shortcut file. This initiates a multi-stage process involving privilege escalation, disabling Microsoft Defender, and downloading further malicious payloads.