Skip to main content

Tag: hollowframe loader

2 articles

Law firm's office interior with scattered papers and out-of-focus laptop screen.

HollowFrame Loader Evades Defender with Fake Python DLL Tactic

Clever attackers have found a way to slip past Microsoft Defender by using a fake Python DLL, effectively creating a trusted execution lane that evades detection. They set the stage for this trick by first gaining elevated access through a sneaky spear-phishing link.

Analyst 207
Law firm's office interior with desk, chair, and subtle computer setup.

HollowFrame Loader Deploys Matryoshka Backdoor in Targeted Law Firm Attacks

Cyber attackers have deployed a sneaky duo, HollowFrame and Matryoshka, to gain a persistent foothold in targeted law firm attacks, allowing them to execute remote commands, snoop on Active Directory, and transfer files. It all started with a cleverly crafted spear-phishing message containing a malicious link that set off a multi-stage chain of events.

Analyst 207