HackerFeeds

CyberSecurity News

HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm

The Hacker News
· July 31, 2026

AI summary

Researchers have identified a new loader framework called HollowFrame, which is written in Go, and a malware family called Matryoshka, written in Rust. The HollowFrame loader is used to deploy the Matryoshka backdoor in targeted attacks. A recent attack on a law firm began with a spear-phishing email containing a link to an encrypted archive. The archive held a Windows Shortcut file, which when executed, initiated a multi-stage infection chain. The attack ultimately led to the deployment of the Matryoshka backdoor. The discovery was made by cybersecurity researchers at Blackpoint Cyber.

Read the full article at The Hacker Newsthehackernews.com/2026/07/hollowframe-loader-deploys-matryoshka.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.