GitHub Mailboxes Hide a Persistent Law Firm Foothold
A phishing click can turn into a living foothold, not just a dropped file. The missed phase is what happens after open: the attacker hides inside trusted Windows and Python components, then uses normal-looking GitHub traffic to keep control and reduce what defenders see.
Researchers tracked a previously undocumented loader and backdoor pair on two law firm endpoints. The lure was a “Case Documents” shortcut in an encrypted archive, and the payload chain used DLL side-loading through python.exe and python311.dll, scheduled-task persistence, weakened Microsoft Defender protections, and a Matryoshka backdoor with HTTP or GitHub command-and-control for beaconing, tasking, reconnaissance, file transfer, and follow-on payloads.
That means the exposure does not end when the attachment is blocked or removed. Once this foothold is in place, it can support credential theft, lateral movement, and broader domain compromise.