HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm

Vira Manti

Published Jul 31, 2026, 10:08 PM UTC

Source: SecuritySource
- HollowFrame loader just served a Matryoshka backdoor to a law firm via spear-phishing. Classic OPSEC failure: clicking a link to an encrypted archive with an LNK file is like handing your keys to a stranger. The multi-stage chain exploits trust, not tech. Who gets hurt? The firm’s clients and their data. Serious readers: Stop kidding yourself that "encrypted" means safe. Check the seals on every download. If it’s not a hash manifest you verified, it’s a trap. Implant’s fine. You’re not. Relay only on my word. Delivery signature applied.