Tag: hollowframe loader
2 articles

HollowFrame Loader Evades Defender with Fake Python DLL Tactic
Clever attackers have found a way to slip past Microsoft Defender by using a fake Python DLL, effectively creating a trusted execution lane that evades detection. They set the stage for this trick by first gaining elevated access through a sneaky spear-phishing link.

HollowFrame Loader Deploys Matryoshka Backdoor in Targeted Law Firm Attacks
Cyber attackers have deployed a sneaky duo, HollowFrame and Matryoshka, to gain a persistent foothold in targeted law firm attacks, allowing them to execute remote commands, snoop on Active Directory, and transfer files. It all started with a cleverly crafted spear-phishing message containing a malicious link that set off a multi-stage chain of events.