Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
Together, HollowFrame and Matryoshka gave the actor a persistent foothold for remote command execution, Active Directory reconnaissance, file transfer, and deployment of follow-on tooling.
activating a command sequence that employs PowerShell to fetch next-stage components from a remote server
The malicious .lnk launched a command sequence that wrote Base64 encoded content into %TEMP%\sgrfm.b64 , generated a companion %TEMP%\sgrfm.cmd script, and invoked certutil.exe -decode to reconstruct the next command stage.
The loader supported several execution modes, including p3_poison, phantom_dll, process_ghosting, module_stomping, and file_based . | Additional execution paths included Process Ghosting, module stomping, manual PE mapping, shellcode execution, NtCreateThreadEx based execution, PEB image base patching
Persistence options included... a permanent WMI event subscription triggered by new Win32_LogonSession instances
It converted each byte from hexadecimal, XORed it against the repeating key, rebuilt the decoded script as text, and executed the result through Invoke-Expression.
The loader supported several execution modes, including p3_poison, phantom_dll, process_ghosting, module_stomping, and file_based . | Additional execution paths included Process Ghosting, module stomping, manual PE mapping, shellcode execution, NtCreateThreadEx based execution, PEB image base patching
13 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A previously undocumented Go-based modular loader and persistence framework delivered via spear-phishing and DLL side-loading. It performs anti-analysis checks, weakens Microsoft Defender protections, establishes persistence via a scheduled task, unpacks an encrypted container, and deploys follow-on payloads including Matryoshka.
A modular Go-based loader and persistence framework used after phishing-based initial access. It decrypts and launches embedded payloads, supports multiple execution techniques such as process ghosting, module stomping, manual PE mapping, shellcode execution, and file-based launch, and establishes persistence via scheduled tasks, WMI event subscriptions, and Startup-folder deployment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.