HollowFrame 로더가 로펌에 대해 Matryoshka 백도어를 배포한 피싱 공격을 진행했습니다.
HollowFrame이라는 Go 기반 로더 프레임워크와 Matryoshka라는 Rust 기반 맬웨어 가족이 발견되었습니다. Blackpoint Cyber에 따르면, 해당 공격은 로펌을 겨냥한 전자우편 피싱 메시지로 시작되며, 암호화된 아카이브 링크를 포함하고 있습니다. 이 파일을 실행하면 다단계 체인이 시작되어 시스템에 백도어가 설치됩니다.
HollowFrame loader deploys Matryoshka backdoor in spear-phishing attacks targeting law firms.
A previously undocumented Go-based loader framework named HollowFrame and a Rust-based malware family called Matryoshka have been identified. According to Blackpoint Cyber, the intrusion begins with a spear-phishing message that contains a link to an encrypted archive. Executing a file from this archive initiates a multi-stage chain leading to the deployment of a backdoor on the victim's system.