Security News

Cybersecurity news aggregator

HIGH Attacks SC Media

New HollowFrame loader and Matryoshka malware family discovered

A new multi-stage attack chain uses spear-phishing emails with encrypted archives to deploy the HollowFrame loader and Matryoshka backdoor. HollowFrame employs DLL side-loading via Python and anti-analysis checks, while the Rust-based Matryoshka malware uses HTTP or a private GitHub repository for C2. This modular, multi-language approach complicates detection and attribution by obscuring each stage of the infection.
Read Full Article →

Malware New HollowFrame loader and Matryoshka malware family discovered July 31, 2026 Share By SC Staff (Adobe Stock) A new Go-based loader framework named HollowFrame and a Rust-based malware family called Matryoshka have been identified by cybersecurity researchers at Blackpoint Cyber. These tools were used in a sophisticated attack targeting a law firm, demonstrating advanced techniques for initial access and persistence, based on information published by The Hacker News. The attack chain begins with a spear-phishing email containing a link to an encrypted archive. This archive holds a Windows Shortcut (LNK) file that, when executed, initiates a multi-stage process. This process includes privilege escalation, disabling Microsoft Defender protections, and downloading further payloads. HollowFrame, the loader, uses a DLL side-loading technique with the legitimate Python binary. It also incorporates anti-analysis checks based on system uptime, memory, file count, and cursor movement to evade sandboxed environments. Persistence is achieved through scheduled tasks. The Matryoshka backdoor, written in Rust, has two variants: one using HTTP for command and control (C2), and another leveraging a private GitHub repository for C2 communication, tasking, reconnaissance, and file transfer. This modular approach, with each stage obscuring the previous one, complicates detection and attribution, making it difficult to identify the full infection logic or the complete C2 infrastructure. Source: The Hacker News SC Staff Related Malware Cryptomining campaign avoids root access to evade detection SC Staff July 31, 2026 The campaign, identified in May 2026 by Group-IB, uses a modified XMRig miner. Malware Flying Eagle Android RAT source code circulates on Telegram SC Staff July 29, 2026 The Flying Eagle framework is being distributed as a fake "公安一网通办" Public Security service application targeting Android users in China. Malware Italian organizations targeted by 148 ransomware attacks in first half of 2026 SC Staff July 28, 2026 Italian organizations faced 148 confirmed ransomware attacks in the first half of 2026, with the manufacturing sector being the most frequently targeted. Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Adware You can skip this ad in 5 seconds

Share this article