Matryoshka is a name used for Windows remote-access malware, including a Rust-based backdoor family deployed alongside the Go-based HollowFrame loader. The Rust family has two documented variants: an HTTP-based implant supporting remote command execution and additional tooling delivery, and a GitHub-based implant using a private repository for victim-specific beaconing, tasking, command results, file transfer, and secondary payload retrieval. Its reconnaissance functionality includes identifying domain controllers, enumerating domain computers and privileged groups, and collecting network configuration, token privileges, and installed software information.
The Rust backdoors were deployed in a spear-phishing intrusion affecting two endpoints at a law firm. A legal-document lure led recipients to an encrypted archive containing a malicious Windows shortcut, which initiated staged PowerShell execution and payload retrieval. HollowFrame subsequently deployed Matryoshka through DLL sideloading involving a legitimate Microsoft OneDrive updater. The HTTP implant executed operator commands inside the trusted process, while the GitHub implant used a proxy DLL exposing Windows Terminal Services functions. The campaign's operators have not been identified.
The Matryoshka name also identifies the Windows remote-access trojan tracked as S0167. Its documented capabilities include stealing Microsoft Outlook passwords, capturing screenshots, providing Meterpreter shell access, and using reflective DLL injection to execute its malicious library. It can maintain persistence through scheduled tasks and Registry-based logon autostart entries. These older capabilities are distinct from the documented functionality of the Rust backdoor variants.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
31 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
placing the first Matryoshka backdoor's command execution and network traffic inside a trusted Microsoft process.
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
A link routed recipients through an attacker-controlled redirector to an encrypted archive hosted on Mega, containing a shortcut file named Case Documents.lnk. Executing it wrote Base64 content to a temporary file, rebuilt a script using the built-in certutil utility, then launched an obfuscated PowerShell chain
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
Aria-body has the ability to inject itself into another process such as rundll32.exe and dllhost.exe... BlackEnergy injects its DLL component into svchost.exe... ComRAT has injected its orchestrator DLL into explorer.exe... Stuxnet injects an entire DLL into an existing, newly created, or preselected trusted process.
Matryoshka ... After downloading the first-stage payload, it runs the second-stage malware via its dropper and installs the real payload. It uses the process hollowing technique to evade defenses.
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
A link routed recipients through an attacker-controlled redirector to an encrypted archive hosted on Mega, containing a shortcut file named Case Documents.lnk. Executing it wrote Base64 content to a temporary file, rebuilt a script using the built-in certutil utility, then launched an obfuscated PowerShell chain
The archive it retrieved was named to resemble an official Python embedded distribution, though the filename read amd96 rather than amd64.
Aria-body has the ability to inject itself into another process such as rundll32.exe and dllhost.exe... BlackEnergy injects its DLL component into svchost.exe... ComRAT has injected its orchestrator DLL into explorer.exe... Stuxnet injects an entire DLL into an existing, newly created, or preselected trusted process.
Matryoshka ... After downloading the first-stage payload, it runs the second-stage malware via its dropper and installs the real payload. It uses the process hollowing technique to evade defenses.
Cobalt Strike has the ability to load DLLs via reflective injection... Lazarus Group malware sample performs reflective DLL injection... Matryoshka uses reflective DLL injection... Netwalker DLL has been injected reflectively into the memory of a legitimate running process.
and inventory network configuration, local privileges and installed software.
Beyond shell access, the variant could identify domain controllers, enumerate domain computers and privileged group membership
and inventory network configuration, local privileges and installed software.
Beyond shell access, the variant could identify domain controllers, enumerate domain computers and privileged group membership
These capabilities could support credential theft, lateral movement, and broader domain compromise
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
33 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A pair of Rust backdoor variants delivered by HollowFrame. One variant is sideloaded through a malicious version.dll beside a legitimate OneDrive updater to hide execution in a trusted Microsoft process. Another variant uses a wtsapi32.dll proxy and GitHub as a dead-drop C2 channel with per-victim directories for beaconing, commands, results, and file transfer. It supports shell access, domain controller discovery, domain and privilege enumeration, and host/network inventory.
A Rust-based backdoor with two observed variants: one using HTTP C2 and another using a private GitHub repository for C2. It enables remote command execution, beaconing, reconnaissance, file transfer, shell spawning, and delivery of secondary payloads.
A Windows backdoor in the reported intrusion chain, associated with document-lure phishing, PowerShell staging, Defender exclusion changes, staged Python files, and persistent remote-access behavior.
A Rust-based backdoor malware family with at least two variants. It supports C2 over HTTP or via a private GitHub repository and is used for tasking, reconnaissance, and file transfer as part of a modular, multi-stage attack chain.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.