Find notable cyber news and cases, enriched with sources, timelines, and signals.

HollowFrame and Matryoshka fake Python DLL sideloading activity

Malware Activity
First reported
Last updated
Happening score
H score 23
1 unique sources, 1 articles

Summary

Hide ▲

The HollowFrame loader and Matryoshka backdoors were delivered through a counterfeit Python runtime, turning a spear phishing chain into trusted-process abuse on two endpoints at a law firm. The operators added Defender exclusions for `python.exe`, then used DLL sideloading to hand execution to malicious Go and Rust payloads. One Matryoshka variant also used GitHub as a covert tasking and file-transfer channel.

Related Happenings

Fake AI study guide AsyncRAT lure campaign targeting Windows users

Campaign
H score33 First: 11.06.2026 17:00 Last: 11.06.2026 17:00 Sources 1

About this happening: A malware-luring campaign now uses fake AI study guides and developer resources to target Windows users at organizations, increasing the risk of stealthy AsyncRA...

Shai-Hulud PyPI supply-chain malware activity

Malware Activity
H score22 First: 08.06.2026 23:41 Last: 08.06.2026 23:41 Sources 1

About this happening: The Shai-Hulud supply-chain malware compromised 19 PyPI packages, turning routine installs into secret-stealing execution and putting developer credentials at risk. Th...

GlassWorm supply-chain malware activity

Malware Activity
H score22 First: 27.05.2026 14:48 Last: 27.05.2026 14:48 Sources 1

About this happening: The GlassWorm malware activity is now under a coordinated C2 disruption, reducing its ability to deliver new instructions and payloads to infected developer systems. The o...

Fake Claude PlugX phishing campaign

Campaign
H score34 First: 13.04.2026 12:52 Last: 13.04.2026 12:52 Sources 1

About this happening: A February phishing campaign used a fake Claude website and fake meeting invitations to deliver PlugX malware to recipients, turning a popular AI brand into a malw...

Latest development: 07.05.2026 13:02

A fake Claude AI site at claude-pro[.]com distributed Claude-Pro-windows-x64.zip, which drops NOVupdate.exe, NOVupdate.exe.dat, and avk.dll to sideload DonutLoader and load the Beagle backdoor on Windows. The backdoor uses license[.]claude-pro[.]com for command-and-control over TCP 443 and/or UDP 8080, and related Beagle samples were submitted to VirusTotal between February and April this year.

BlackSanta EDR killer malware activity targeting HR departments

Malware Activity
H score20 First: 11.03.2026 00:57 Last: 11.03.2026 00:57 Sources 1

About this happening: The BlackSanta malware operation has run for more than a year, targeting HR departments and using an EDR killer to weaken host defenses before payload execution. T...

Timeline

  1. 30.07.2026 03:00 2 articles · 4d ago

    Fake Python runtime delivers HollowFrame and Matryoshka to a law firm

    Initial Disclosure

    A spear-phishing chain against two endpoints at a law firm used an attacker-controlled redirector, a Mega-hosted archive containing `Case Documents.lnk`, `certutil`, and obfuscated PowerShell to deliver HollowFrame and Matryoshka. The operators set Microsoft Defender exclusions for a staging directory and `python.exe`, then sideloaded a counterfeit `python311.dll` that was actually a 64-bit Go library; another branch sideloaded a malicious `version.dll` beside a legitimate OneDrive updater, and a Rust `wtsapi32.dll` variant later used GitHub as a covert tasking and file-transfer channel.

    Show sources