🟠 High | Source: The Hacker News
Researchers have uncovered a new attack chain targeting a law firm via spear-phishing, using a Go-based loader called HollowFrame and a Rust-based backdoor named Matryoshka. The attack begins with a malicious link in a phishing email leading to an encrypted archive containing a Windows Shortcut file, which triggers a multi-stage infection sequence. The use of lesser-known programming languages and layered delivery techniques suggests a deliberate effort to evade detection.
Security Architect’s Take: Enforce email gateway controls to block or quarantine encrypted archives and LNK file attachments, and ensure endpoint detection tooling has coverage for Go and Rust-based binaries. Review egress filtering and lateral movement controls for environments handling sensitive legal or professional services data, as law firms are high-value targets for espionage-motivated threat actors.
Original advisory: HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm