Matryoshka is a Rust-based backdoor family deployed in attacks on law firms. It comes in two variants: one uses HTTP-based communication for command execution, while the other leverages a private GitHub repository for command-and-control. The GitHub variant uses per-host mailboxes to manage tasking and results, enabling beaconing, reconnaissance, file transfer, and payload delivery. The backdoor communicates with C2 servers over HTTP and can spawn shells.