A previously undocumented threat group has been identified, distributing its malicious activity through a spear phishing chain that delivers an encrypted archive containing a malicious Windows shortcut. The campaign's distribution is widespread and affects multiple endpoints at law firms. The threat leverages a modular Go based loader tracked as HollowFrame to provide the actor with multiple execution and persistence options. HollowFrame uses a staged Python environment to disguise its execution, loading through a malicious executable, decrypting, and launching a modular framework designed to support payload execution and persistence techniques.
This loader framework also includes evasion mechanisms such as obfuscated PowerShell sequences that request elevation, weaken Microsoft Defender protections, and download additional payloads. The threat further employs two distinct Rust based backdoor variants of the Matryoshka family for HTTP-based communication and command execution, and GitHub-based beaconing, tasking, reconnaissance, file transfer, and secondary payload delivery.[/subscribe_to_unlock_form]
A previously undocumented threat group has been identified, distributing its malicious activity through a spear phishing chain that delivers an encrypted archive containing a malicious Windows shortcut. The campaign's distribution is widespread and affects multiple endpoints at law firms. The threat leverages a modular Go based loader tracked as HollowFrame to provide the actor with multiple execution and persistence options. HollowFrame uses a staged Python environment to disguise its execution, loading through a malicious executable, decrypting, and launching a modular framework designed to support payload execution and persistence techniques.
This loader framework also includes evasion mechanisms such as obfuscated PowerShell sequences that request elevation, weaken Microsoft Defender protections, and download additional payloads. The threat further employs two distinct Rust based backdoor variants of the Matryoshka family for HTTP-based communication and command execution, and GitHub-based beaconing, tasking, reconnaissance, file transfer, and secondary payload delivery.[emaillocker id="1283"]
The campaign's defining characteristic is its deliberate fragmentation, concealing malicious activity behind legitimate runtimes, signed applications, familiar Windows components, and widely used cloud services. This layered design makes the intrusion more difficult to identify and reconstruct through any single source of telemetry.
| Tactic | Technique Id | Technique | Sub-technique |
|---|---|---|---|
| Initial access | T1566.001 | Phishing | Spearphishing Attachment |
| Execution | T1059.001 | Command and Scripting Interpreter | PowerShell |
| Persistence | T1547.001 | Boot or Logon Autostart Execution | Registry Run Keys / Startup Folder |
| Defence Evasion | T1027 | Obfuscated Files or Information | - |
| Discovery | T1082 | System Information Discovery | - |
| Lateral Movement | T1021.001 | Remote Services | Remote Desktop Protocol |
| Command and control | T1071.001 | Application Layer Protocol | Web Protocols |
| Command and control | T1573.001 | Encrypted Channel | Symmetric Cryptography |
| Exfiltration | T1041 | Exfiltration Over C2 Channel | - |
| Objective | Behavior ID | Behavior |
|---|---|---|
| Defense Evasion | B0029 | Polymorphic Code |
| Anti-Static Analysis | B0032 | Executable Code Obfuscation |
| Command & Control | B0030 | C2 Communication |
| Impact | B0022 | Remote Access |
| Discovery | E1082 | System Information Discovery |
| Execution | E1204 | User Execution |
| Exfiltration | E1020 | Automated Exfiltration |
| Persistence | F0012 | Registry Run Keys / Startup Folder |
| Defense Evasion | F0004 | Disable or Evade Security Tools |
| Discovery | E1083 | File and Directory Discovery |
The following reports contain further technical details:
[/emaillocker]