www.infosecurity-magazine.com 8/3/2026, 12:01:50 PM · external

HollowFrame loader evades Defender via fake Python in law firm

HollowFrame loader evades Defender via fake Python in law firm
CyberSIXT Evidence Panel
Primary Source blackpointcyber.com

THE article discusses the discovery of a new loader framework known as HollowFrame, which uses a counterfeit Python runtime to evade Microsoft Defender detection. This framework was utilized in a cyber intrusion targeting a law firm, initiated through a spear phishing attack that redirected users to download malicious content. After gaining administrator privileges, the malware created exclusions in Defender settings, facilitating the download and execution of further malicious payloads.

The HollowFrame loader employs various techniques to maintain persistence and evade detection, including DLL sideloading and using GitHub as a covert channel for communication and task management. Recommendations for defense include monitoring unusual GitHub activity and reviewing scheduled tasks.

View Primary Source Via www.infosecurity-magazine.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline