Threat Advisory

HollowFrame Loader Framework Grants Persistent Remote Access with Matryoshka Backdoors

Threat: Malware
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A previously undocumented threat group has been identified, distributing its malicious activity through a spear phishing chain that delivers an encrypted archive containing a malicious Windows shortcut. The campaign's distribution is widespread and affects multiple endpoints at law firms. The threat leverages a modular Go based loader tracked as HollowFrame to provide the actor with multiple execution and persistence options. HollowFrame uses a staged Python environment to disguise its execution, loading through a malicious executable, decrypting, and launching a modular framework designed to support payload execution and persistence techniques.

This loader framework also includes evasion mechanisms such as obfuscated PowerShell sequences that request elevation, weaken Microsoft Defender protections, and download additional payloads. The threat further employs two distinct Rust based backdoor variants of the Matryoshka family for HTTP-based communication and command execution, and GitHub-based beaconing, tasking, reconnaissance, file transfer, and secondary payload delivery.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A previously undocumented threat group has been identified, distributing its malicious activity through a spear phishing chain that delivers an encrypted archive containing a malicious Windows shortcut. The campaign's distribution is widespread and affects multiple endpoints at law firms. The threat leverages a modular Go based loader tracked as HollowFrame to provide the actor with multiple execution and persistence options. HollowFrame uses a staged Python environment to disguise its execution, loading through a malicious executable, decrypting, and launching a modular framework designed to support payload execution and persistence techniques.

This loader framework also includes evasion mechanisms such as obfuscated PowerShell sequences that request elevation, weaken Microsoft Defender protections, and download additional payloads. The threat further employs two distinct Rust based backdoor variants of the Matryoshka family for HTTP-based communication and command execution, and GitHub-based beaconing, tasking, reconnaissance, file transfer, and secondary payload delivery.[emaillocker id="1283"]

The campaign's defining characteristic is its deliberate fragmentation, concealing malicious activity behind legitimate runtimes, signed applications, familiar Windows components, and widely used cloud services. This layered design makes the intrusion more difficult to identify and reconstruct through any single source of telemetry.

THREAT PROFILE:

Tactic Technique Id Technique Sub-technique
Initial access T1566.001 Phishing Spearphishing Attachment
Execution T1059.001 Command and Scripting Interpreter PowerShell
Persistence T1547.001 Boot or Logon Autostart Execution Registry Run Keys / Startup Folder
Defence Evasion T1027 Obfuscated Files or Information -
Discovery T1082 System Information Discovery -
Lateral Movement T1021.001 Remote Services Remote Desktop Protocol
Command and control T1071.001 Application Layer Protocol Web Protocols
Command and control T1573.001 Encrypted Channel Symmetric Cryptography
Exfiltration T1041 Exfiltration Over C2 Channel -

MBC MAPPING:

Objective Behavior ID Behavior
Defense Evasion B0029 Polymorphic Code
Anti-Static Analysis B0032 Executable Code Obfuscation
Command & Control B0030 C2 Communication
Impact B0022 Remote Access
Discovery E1082 System Information Discovery
Execution E1204 User Execution
Exfiltration E1020 Automated Exfiltration
Persistence F0012 Registry Run Keys / Startup Folder
Defense Evasion F0004 Disable or Evade Security Tools
Discovery E1083 File and Directory Discovery

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu