Law firm hit by network compromise
Incident
Summary
Hide ▲
Show ▼
A spear-phishing intrusion against a law firm used a malicious LNK to deploy HollowFrame and Matryoshka, giving the operator a persistent foothold for remote command execution and reconnaissance. The intrusion reached two endpoints and used PowerShell to pull next-stage components from 2.26.252[.]84.
Timeline
-
31.07.2026 19:39 2 articles · 2h ago
HollowFrame and Matryoshka compromise two law firm endpoints
Initial DisclosureResearchers disclosed a spear-phishing intrusion against an unspecified law firm that used an encrypted archive with an LNK lure to trigger PowerShell retrieval from 2.26.252[.]84, DLL side-loading with python.exe and python311.dll, and a second side-loading chain to deploy Matryoshka. The activity targeted two endpoints and established a persistent foothold for remote command execution, Active Directory reconnaissance, file transfer, anti-analysis evasion, and follow-on tooling delivery.
Show sources
- HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm — thehackernews.com — 31.07.2026 19:39
- HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm — thehackernews.com — 31.07.2026 19:39