Spear‑phishing an Italian Law Firm: HollowFrame and Matryoshka Use DLL Side‑loading and a GitHub Repo as C2 Channel

A spear-phishing campaign targeted an Italian law firm, deploying the HollowFrame loader and Matryoshka backdoor via DLL side-loading and GitHub as C2.

Spear‑phishing an Italian Law Firm: HollowFrame and Matryoshka Use DLL Side‑loading and a GitHub Repo as C2 Channel
Malware

Illustrative image generated with AI

A spear‑phishing campaign targeted an unspecified Italian law firm, delivering an encrypted archive containing an LNK file named Case Documents. Executing the shortcut launched a PowerShell chain, paving the way for the modular HollowFrame loader and, immediately after, the Matryoshka backdoor. The attack was detected on July 31, 2026 and shows a high level of sophistication: the two malicious stages combine DLL side‑loading, multi‑layer encryption, and – in one of the two backdoor variants – the use of a private GitHub repository as a command and control center. Attribution remains unknown, but the capabilities obtained allow lateral movement up to compromising the entire Active Directory domain.

The Initial Chain: From an LNK to a Double PowerShell Execution

The originating email mimicked legal communications and included a password‑protected compressed archive. Inside, the only visible item was the Case Documents.lnk file. A double‑click triggered a hostile two‑stage PowerShell sequence: the first leverages the HollowFrame loader; the second, activated by the loader itself, drops the Matryoshka backdoor. All components are native Windows and require no specific exploit for initial execution, relying instead on user deception.

HollowFrame: The Go Loader Disguised as python.exe

HollowFrame is a modular loader written in Go. It is deployed through a DLL side‑loading technique: it uses the legitimate python.exe executable (signed and unmodified) alongside a malicious python311.dll, which executes the loader code upon simply launching the Python interpreter. Inside the DLL is an encrypted container: once decrypted, a second side‑loading chain activates, this time to load the Matryoshka backdoor. The next step involves an equally malicious version.dll, which brings the final Rust payload into memory.

The choice to abuse Python adds a veneer of legitimacy: the python.exe process is signed, commonly used, and rarely blocked in enterprise environments. The use of separate encrypted containers also makes static analysis and immediate detection more difficult.

Matryoshka: Two Variants, One Goal

The Matryoshka backdoor is written in Rust and exists in at least two distinct variants, differentiated by the command and control channel adopted.

The first variant uses a simple HTTP dialogue with a remote C2 server. The second, far more unusual, turns a private GitHub repository into its operational hub. The incriminated repository is adioziaete/memio, associated with a GitHub account created on January 6, 2023 and last updated on June 7, 2026. For each infected machine, Matryoshka creates a dedicated directory inside the repo and deposits JSON files with three functions: beaconing (to report system status), command reception, and result submission. The attacker reads and writes to these directories using the GitHub interface, blending traffic with normal platform communications.

Both variants share the same capabilities: remote command execution, Active Directory enumeration, file transfer, and distribution of additional tools. The two‑stage architecture – loader plus backdoor – and the dual C2 channel make the whole resilient and difficult to eradicate wholesale.

What the Firm (and Any Affected Company) Risks

Once the attacker gains an initial foothold, they can:

  • install scheduled tasks to maintain persistence;
  • execute commands with the victim’s privileges and, when successful, escalate privileges by temporarily disabling Microsoft Defender;
  • collect Active Directory domain information, mapping users, groups, and permissions;
  • exfiltrate confidential documents and introduce secondary payloads, such as ransomware or lateral movement tools.

The severity is high because the HollowFrame–Matryoshka combination provides stealthy, modular access potentially capable of compromising the entire corporate infrastructure, not just the single PC hit by the email.

Indicators and Initial Countermeasures

To date, no official mitigations have been released by the involved vendors. However, the investigations have provided some indicators of compromise (IOCs) usable for detection:

  • HTTP C2 IPs: 2.26.252[.]84 and 45.158.196[.]184:8888
  • GitHub repository: adioziaete/memio
  • Side‑loading combinations: presence of python.exe from non‑standard paths together with unsigned python311.dll
  • Suspicious PowerShell executions triggered by LNK files
  • Anomalous scheduled tasks created around the time of infection
  • Network traffic to GitHub repositories not justified by normal business activities

Those managing Windows environments can implement monitoring for these indicators and check, using EDR tools, for the described side‑loading chains. If in doubt, isolating the system and initiating a forensic analysis of the entire domain remains the safest path.

Read next

Sources

This article is an original reworking based on the sources below.

Back to home

Latest Cybersecurity News

All cybersecurity news →