StrikeShark Campaign Unleashes SharkLoader Malware to Deploy Cobalt Strike

StrikeShark Campaign Unleashes SharkLoader Malware to Deploy Cobalt Strike

3h ago Securelistelliotonsecurity.comGbhackerswww.kaspersky.com 87% similarity 64.4
Share:

Article Content

Browse articles
ThreatCluster

A newly discovered malware family named SharkLoader has been identified as part of a campaign called StrikeShark, targeting a diplomatic organization in Indonesia. SharkLoader acts as a loader to deploy Cobalt Strike Beacon on compromised systems. The campaign has expanded to affect multiple countries, including Taiwan, Colombia, and several others across various sectors. Attack methods include exploiting vulnerabilities in internet-facing applications such as Microsoft Exchange (CVE-2021-26855) and Openfire (CVE-2023-32315). The threat actor's tactics involve both exploitation of known vulnerabilities and the use of custom dropper samples. Attribution to a specific threat actor remains uncertain, although the tools used suggest a connection to Chinese-speaking developers. The campaign's objectives are still under investigation.

Key Points: • SharkLoader malware is being used to deploy Cobalt Strike in a multi-country campaign. • Exploitation of CVE-2021-26855 and CVE-2023-32315 has been observed in attacks. • The campaign targets diverse sectors, including government and software development organizations.

ThreatCluster AI

Timeline

2021-03-02
CVE-2021-26855 published
A critical vulnerability in Microsoft Exchange allowing remote code execution was published.
Securelist
2021-03-11
CVE-2021-27076 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2023-05-26
CVE-2023-32315 published
A vulnerability in Openfire was published, later exploited in the StrikeShark campaign.
Securelist
2024-07-01
CVE-2024-36401 published
A vulnerability in GeoServer was published, used in attacks against Colombian organizations.
Securelist
2026-06-24
StrikeShark campaign revealed
Research uncovered the SharkLoader malware and its deployment of Cobalt Strike across multiple countries.
Securelist
2026-06-25
Gbhackers report on StrikeShark
Gbhackers published findings on the SharkLoader malware and its implications for cybersecurity.
Gbhackers

Community

Browse all →