HollowFrame is a previously undocumented Go-based loader framework used in a spear-phishing attack targeting a law firm. It is launched via DLL side-loading with legitimate Python binaries and rogue DLLs. The loader performs anti-analysis checks based on system uptime, memory, file count, and cursor movement, and establishes persistence via scheduled tasks. It contains an encrypted container that unpacks to deploy the Matryoshka backdoor.