Matryoshka is a Rust-based Windows backdoor family observed in a multi-stage intrusion chain in which a Go-based loader framework deployed the final implant through DLL sideloading and reflective DLL injection. It has been documented in at least two variants: one using direct HTTP command-and-control and another using a private GitHub repository as a dead-drop channel for beaconing, tasking, result submission, file transfer, reconnaissance, and secondary payload delivery. The malware has been associated with an intrusion targeting a law firm, where it was delivered after a spearphishing-triggered loader sequence that abused a shortcut file, PowerShell, staged payload retrieval, and a fake embedded Python environment.
Matryoshka provides persistent remote access and post-compromise control. Reported capabilities include command execution, shell access, screen capture, file transfer, secondary payload delivery, and Outlook password theft. The GitHub-backed variant also performs host and Active Directory reconnaissance, including identifying domain controllers, enumerating domain computers and privileged group membership, and collecting network configuration, local privilege, and installed software information. The malware has been observed executing within trusted Windows processes and using sideload hosts to blend malicious activity with legitimate software behavior.
For persistence, Matryoshka has been observed creating Registry Run entries and scheduled tasks with legitimate-looking names. For execution and evasion, it uses reflective DLL injection to load a malicious library and run the RAT in memory. The broader intrusion chain also established Microsoft Defender exclusions before downloading later stages, indicating deliberate defense evasion in the surrounding deployment workflow. The threat actor behind the observed activity remains unknown.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
31 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
placing the first Matryoshka backdoor's command execution and network traffic inside a trusted Microsoft process.
Executing it wrote Base64 content to a temporary file, rebuilt a script using the built-in certutil utility, then launched an obfuscated PowerShell chain that prompted the user for administrator rights.
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
A link routed recipients through an attacker-controlled redirector to an encrypted archive hosted on Mega, containing a shortcut file named Case Documents.lnk. Executing it wrote Base64 content to a temporary file, rebuilt a script using the built-in certutil utility, then launched an obfuscated PowerShell chain
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
Aria-body has the ability to inject itself into another process such as rundll32.exe and dllhost.exe... BlackEnergy injects its DLL component into svchost.exe... ComRAT has injected its orchestrator DLL into explorer.exe... Stuxnet injects an entire DLL into an existing, newly created, or preselected trusted process.
Matryoshka ... After downloading the first-stage payload, it runs the second-stage malware via its dropper and installs the real payload. It uses the process hollowing technique to evade defenses.
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
A link routed recipients through an attacker-controlled redirector to an encrypted archive hosted on Mega, containing a shortcut file named Case Documents.lnk. Executing it wrote Base64 content to a temporary file, rebuilt a script using the built-in certutil utility, then launched an obfuscated PowerShell chain
Running it launched a command chain that wrote Base64 content into %TEMP%\sgrfm.b64...
The archive it retrieved was named to resemble an official Python embedded distribution, though the filename read amd96 rather than amd64.
Aria-body has the ability to inject itself into another process such as rundll32.exe and dllhost.exe... BlackEnergy injects its DLL component into svchost.exe... ComRAT has injected its orchestrator DLL into explorer.exe... Stuxnet injects an entire DLL into an existing, newly created, or preselected trusted process.
Matryoshka ... After downloading the first-stage payload, it runs the second-stage malware via its dropper and installs the real payload. It uses the process hollowing technique to evade defenses.
Running it launched a command chain that wrote Base64 content into %TEMP%\sgrfm.b64 , created %TEMP%\sgrfm.cmd , used certutil.exe -decode...
Cobalt Strike has the ability to load DLLs via reflective injection... Lazarus Group malware sample performs reflective DLL injection... Matryoshka uses reflective DLL injection... Netwalker DLL has been injected reflectively into the memory of a legitimate running process.
and inventory network configuration, local privileges and installed software.
Beyond shell access, the variant could identify domain controllers, enumerate domain computers and privileged group membership
and inventory network configuration, local privileges and installed software.
Beyond shell access, the variant could identify domain controllers, enumerate domain computers and privileged group membership
another leveraging a private GitHub repository for C2 communication, tasking, reconnaissance, and file transfer.
These capabilities could support credential theft, lateral movement, and broader domain compromise
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
30 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A pair of Rust backdoor variants delivered by HollowFrame. One variant is sideloaded through a malicious version.dll beside a legitimate OneDrive updater to hide execution in a trusted Microsoft process. Another variant uses a wtsapi32.dll proxy and GitHub as a dead-drop C2 channel with per-victim directories for beaconing, commands, results, and file transfer. It supports shell access, domain controller discovery, domain and privilege enumeration, and host/network inventory.
A Rust-based backdoor with two observed variants: one using HTTP C2 and another using a private GitHub repository for C2. It enables remote command execution, beaconing, reconnaissance, file transfer, shell spawning, and delivery of secondary payloads.
A Windows backdoor in the reported intrusion chain, associated with document-lure phishing, PowerShell staging, Defender exclusion changes, staged Python files, and persistent remote-access behavior.
A Rust-based backdoor malware family with at least two variants. It supports C2 over HTTP or via a private GitHub repository and is used for tasking, reconnaissance, and file transfer as part of a modular, multi-stage attack chain.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.