HollowFrame and Matryoshka fake Python DLL sideloading activity
Malware Activity
Summary
Hide ▲
Show ▼
The HollowFrame loader and Matryoshka backdoors were delivered through a counterfeit Python runtime, turning a spear phishing chain into trusted-process abuse on two endpoints at a law firm. The operators added Defender exclusions for `python.exe`, then used DLL sideloading to hand execution to malicious Go and Rust payloads. One Matryoshka variant also used GitHub as a covert tasking and file-transfer channel.
Related Happenings
Fake AI study guide AsyncRAT lure campaign targeting Windows users
Campaign
H score33
First: 11.06.2026 17:00
Last: 11.06.2026 17:00
Sources 1
About this happening:
A malware-luring campaign now uses fake AI study guides and developer resources to target Windows users at organizations, increasing the risk of stealthy AsyncRA...
Fake AI study guide AsyncRAT lure campaign targeting Windows users
CampaignAbout this happening: A malware-luring campaign now uses fake AI study guides and developer resources to target Windows users at organizations, increasing the risk of stealthy AsyncRA...
Shai-Hulud PyPI supply-chain malware activity
Malware Activity
H score22
First: 08.06.2026 23:41
Last: 08.06.2026 23:41
Sources 1
About this happening:
The Shai-Hulud supply-chain malware compromised 19 PyPI packages, turning routine installs into secret-stealing execution and putting developer credentials at risk. Th...
Shai-Hulud PyPI supply-chain malware activity
Malware ActivityAbout this happening: The Shai-Hulud supply-chain malware compromised 19 PyPI packages, turning routine installs into secret-stealing execution and putting developer credentials at risk. Th...
GlassWorm supply-chain malware activity
Malware Activity
H score22
First: 27.05.2026 14:48
Last: 27.05.2026 14:48
Sources 1
About this happening:
The GlassWorm malware activity is now under a coordinated C2 disruption, reducing its ability to deliver new instructions and payloads to infected developer systems. The o...
GlassWorm supply-chain malware activity
Malware ActivityAbout this happening: The GlassWorm malware activity is now under a coordinated C2 disruption, reducing its ability to deliver new instructions and payloads to infected developer systems. The o...
Fake Claude PlugX phishing campaign
Campaign
H score34
First: 13.04.2026 12:52
Last: 13.04.2026 12:52
Sources 1
About this happening:
A February phishing campaign used a fake Claude website and fake meeting invitations to deliver PlugX malware to recipients, turning a popular AI brand into a malw...
Fake Claude PlugX phishing campaign
CampaignAbout this happening: A February phishing campaign used a fake Claude website and fake meeting invitations to deliver PlugX malware to recipients, turning a popular AI brand into a malw...
Latest development: 07.05.2026 13:02
A fake Claude AI site at claude-pro[.]com distributed Claude-Pro-windows-x64.zip, which drops NOVupdate.exe, NOVupdate.exe.dat, and avk.dll to sideload DonutLoader and load the Beagle backdoor on Windows. The backdoor uses license[.]claude-pro[.]com for command-and-control over TCP 443 and/or UDP 8080, and related Beagle samples were submitted to VirusTotal between February and April this year.
BlackSanta EDR killer malware activity targeting HR departments
Malware Activity
H score20
First: 11.03.2026 00:57
Last: 11.03.2026 00:57
Sources 1
About this happening:
The BlackSanta malware operation has run for more than a year, targeting HR departments and using an EDR killer to weaken host defenses before payload execution. T...
BlackSanta EDR killer malware activity targeting HR departments
Malware ActivityAbout this happening: The BlackSanta malware operation has run for more than a year, targeting HR departments and using an EDR killer to weaken host defenses before payload execution. T...
Timeline
-
30.07.2026 03:00 2 articles · 4d ago
Fake Python runtime delivers HollowFrame and Matryoshka to a law firm
Initial DisclosureA spear-phishing chain against two endpoints at a law firm used an attacker-controlled redirector, a Mega-hosted archive containing `Case Documents.lnk`, `certutil`, and obfuscated PowerShell to deliver HollowFrame and Matryoshka. The operators set Microsoft Defender exclusions for a staging directory and `python.exe`, then sideloaded a counterfeit `python311.dll` that was actually a 64-bit Go library; another branch sideloaded a malicious `version.dll` beside a legitimate OneDrive updater, and a Rust `wtsapi32.dll` variant later used GitHub as a covert tasking and file-transfer channel.
Show sources
- HollowFrame Loader Uses Fake Python DLL to Evade Defender — www.infosecurity-magazine.com — 03.08.2026 14:26
- HollowFrame Loader Uses Fake Python DLL to Evade Defender — www.infosecurity-magazine.com — 03.08.2026 14:26