Blog

Law Firm Targeted by Double Malware Threat

by | Sep 8, 2026 | GitHub, HollowFrame, Matryoshka, Microsoft Defender, Phishing Email, Python | 0 comments

 

A Law Firm has been targeted by double malware threat.  Two new malware tools have been detected by researchers, and the bad news is that they can sneak past your defenses with ease.

Blackpoint Cyber has discovered that two previously unseen pieces of malware have been combined to target a law firm. One of them is called HollowFrame and helps to establish initial access, while the other is called Matryoshka. It’s likely that you’re not fluent in Russian, but Matryoshka is the Russian name for the traditional Russian dolls – made of wood – that stack inside one another. It’s a fitting metaphor for the malware as it’s multilayered and difficult to see exactly what’s coming next.

Together, HollowFrame and Matryoshka make for a powerful and clever combination.

The Shortcut That Opens Your Network to Chaos

This new campaign starts with a phishing email. The email contains a link to a password-protected archive file that the target is urged to open. Once opened, this file presents the victim with a shortcut file. If this is clicked, the HollowFrame attack begins.

The malware’s first move is to escalate its privileges on the infected PC. It follows this up by disabling Microsoft Defender. This allows HollowFrame to start downloading additional malware in the background. HollowFrame does all of this by using Python, a piece of software typically used for programming. Python’s presence as a trusted application means it arouses little suspicion.

HollowFrame is particularly persistent as it keeps an eye out for signs that it’s being analyzed. Anything which indicates that a test environment is being run – such as how much memory is being used and if the mouse cursor has recently moved – causes HollowFrame to pause all its activity. This is why it’s able to avoid security tools so effectively.

With HollowFrame in place and active, it’s time for Matryoshka to take over as a persistent backdoor. It does this in two ways. Firstly, it sets up a communication channel which takes place over standard web traffic. Secondly, it uses a GitHub repository to send commands, harvest data, and transfer files without ringing any alarm bells.

Staying Safe from a Double Threat

It doesn’t have to be HollowFrame and Matryoshka that attacks your organization. Any combination of malware spells trouble, so you need to remain vigilant. The best ways to stay safe are:

  • Be cautious of unexpected emails: if you receive an unexpected email asking you to either download a file or click a link, you should always be suspicious. These types of emails will often urge you to action this request with a real sense of urgency. In these situations, staying calm is key. Check with an IT professional that the email is safe before doing anything.
  • Keep your software updated: many modern cyberattacks rely on weaknesses in software. This is why it’s crucial that you always install updates for all your software, even if it’s something mundane such as a notepad app. Patching up these security holes can make a huge difference to your network security.
  • Don’t rely on Defender: hackers, as we’ve seen above, can easily turn off Microsoft Defender, so you shouldn’t make it your only form of defense. Instead, use a third-party antimalware tool alongside Defender. This will make things much harder for hackers.

For more ways to secure and optimize your business technology, contact your local IT professionals.