# A Law Firm Got Hit by Malware That Hid Its Command Server Inside GitHub


When attackers want sustained, quiet access to a target, they don't need exotic infrastructure. Sometimes they just need a free GitHub account and a victim who clicks a file named "Case Documents."


That's the core of a newly documented intrusion chain that Blackpoint Cyber researchers Nevan Beal and Sam Decker dissected this week — a two-part malware ecosystem called HollowFrame and Matryoshka that hit at least two endpoints inside an unnamed law firm. The technical elegance here is real, but so is the calculated targeting. Law firms are walking vaults: M&A negotiations, litigation strategy, attorney-client communications, wire transfer instructions. They're high-value enough to justify custom tooling and patient enough operations that attackers can afford to move slowly.


## The Lure Was Built for the Target


The intrusion starts where these things almost always start: a convincing email. The phishing message carried a link to an encrypted archive — the password likely supplied in the message itself, a move that defeats most email attachment sandboxing. Inside: a Windows Shortcut file (LNK) disguised as "Case Documents."


For a law firm employee expecting case materials from opposing counsel, a third party, or a court filing service, that's a plausible filename with low friction to click. That's not an accident. Whoever built this took the time to think about what a lawyer or paralegal expects to receive.


Executing the LNK triggers PowerShell, which reaches out to a staging server at 2.26.252[.]84 and starts pulling down components for the next phase. From there, the infection chain moves through privilege escalation and deliberate Defender weakening before HollowFrame gets established.


## The Russian Doll Logic of HollowFrame


The loader's name is apt, but Matryoshka — the Russian nesting doll — is a better description of how the whole system works. Each layer conceals the next. Each stage reveals only what it needs to.


HollowFrame is written in Go and loads via DLL side-loading: a legitimate Python binary (python.exe) paired with a rogue python311.dll. This is a technique borrowed from the APT playbook. Signed, trusted binaries like Python have a well-established pattern of loading accompanying DLLs by name, and Windows obligingly executes whatever sits in that path. Defenders watching process trees will see python.exe launch — which is normal on machines where developers work, or where Python-based tools are installed.


Before doing anything else, HollowFrame checks whether it's running in a sandbox. It looks at system uptime, installed memory, the number of files in the user profile, and cursor movement. The combination is shrewd: automated sandboxes tend to have low uptimes, sparse file systems, and no human cursor activity. Pass the checks, and HollowFrame unpacks an encrypted container and launches a second side-loading chain to deploy Matryoshka.


Persistence comes via scheduled task — unglamorous but reliable.


## GitHub as a Dead Drop


The most technically interesting piece of this operation is Matryoshka's second variant, the one that uses GitHub for command-and-control.


The researchers found a private GitHub repository (adioziaete/memio) structured as a per-victim mailbox system. Each compromised host got its own directory, named <computer>_<username>. Inside those directories: beacon.json, cmd.json, and result.json — a clean separation between the victim checking in, the operator issuing tasks, and the victim reporting results. File payloads arrived via an upload/ subdirectory.


This is dead-drop tradecraft adapted for modern infrastructure. The operator doesn't need a custom C2 server that might get flagged, blocked, or taken down by a hosting provider. They use GitHub — a service that most corporate security tools are configured to trust, that runs on Microsoft infrastructure, and that has legitimate SSL certificates signed by authorities that nobody's going to blacklist. Blocking GitHub outright breaks development workflows at most organizations. The attacker knows this.


There's a secondary benefit that may not have been fully appreciated even in the original reporting: GitHub maintains version history. Every commit is logged. That means the operator left a versioned record of every tasking interaction — unless they deleted commits or nuked the repository. The account in question was created in January 2023 and was updated as recently as June 7, 2026. That's over three years of potential operational history that law enforcement or researchers could subpoena or analyze if they got there fast enough.


## What the Chain Hides From You


Blackpoint's researchers noted something important about the overall design: each stage actively limits the malicious behavior visible in the stage before it. No single component contains the full infection logic or the complete C2 picture. For analysts doing triage, this is genuinely painful. You find a suspicious DLL, you sandbox it, and it tells you almost nothing about what the full infection looks like. You'd need to see all of it running together, in the right sequence, on a machine that passes the anti-analysis checks.


This is increasingly the design philosophy of professionally-built malware. Individual components are disposable and deniable. Attribution becomes harder because each piece looks vaguely legitimate or incomplete in isolation.


Attribution here remains unknown. The Go/Rust combination, the GitHub C2 architecture, and the law firm targeting don't cleanly match any public cluster as of this writing.


---


## HackWire Analysis


The GitHub C2 technique deserves more attention than it's getting. This isn't the first time threat actors have abused legitimate platforms for command-and-control — Slack, Teams, Discord, Telegram, and even Google Sheets have all served this role in documented campaigns — but the structural sophistication here is a step above. Most platform-abuse C2 implementations are crude: poll a channel, parse a command, execute it. The Matryoshka variant built per-victim directory structures with semantically named JSON files, separating beacon, tasking, and results into discrete files. That's an operational workflow, not an experiment.


It signals something about the operator's discipline: they're thinking about managing multiple victims concurrently without cross-contamination, and they're comfortable enough with GitHub workflows to build around its primitives. This is not a nation-state actor's first rodeo with platform abuse, but it's also not a commodity cybercrime gang running off-the-shelf tools.


For defenders at law firms specifically, the threat model here has some sharp edges. Legal professionals receive documents from external parties constantly — that's the job. File-based phishing works better against lawyers than against, say, a DevOps team that's been trained to distrust unknown executables. The profession also tends to have a high proportion of endpoints where Python is *not* installed by default, which means detecting the DLL side-loading chain via Python anomaly detection is genuinely actionable: flag any execution of python.exe that isn't associated with a sanctioned application install.


Scheduled task persistence combined with Defender weakening suggests the attacker expected to be in this environment for a while. Active Directory reconnaissance capabilities point toward broader domain compromise as the eventual goal. The initial foothold wasn't the endgame.


The pattern to watch is the convergence of professional-services targeting with living-off-the-land and platform-abuse techniques. Law firms, accounting firms, and consulting shops are being approached with the same sophistication previously reserved for defense contractors and financial institutions. The client data they hold is often just as valuable.


— HackWire Editorial


---


## Related Coverage


  • Read more in our [Tools](https://www.hackwire.news/category/tools) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)