Defender Exclusions Became the Attack Path

The real break is that attackers can pre-load Microsoft Defender with exclusions and turn that protection into a blind spot before the payload arrives. In this case, the exclusion for a staging folder and python.exe was set first, so the later launcher and loader landed in a lane Defender had already been told to ignore. Blackpoint says the campaign hit two endpoints at a law firm and delivered two undocumented malware families: HollowFrame, a Go loader disguised as a Python DLL, and Matryoshka, a pair of Rust backdoors. The fake Python runtime was only the delivery shape; the trust failure was the earlier change to Defender policy, which made a normal-looking execution path safer for the attacker than for the defender. Teams that rely on exclusions or allowlists need to treat admin-initiated policy changes as part of the intrusion surface, not just a tuning detail.

Part of the PlainSec briefing for 2026-08-03

Editions

Sources