Skip to content
StrikeShark Campaign Unleashes SharkLoader Malware to Deploy Cobalt Strike

StrikeShark Campaign Unleashes SharkLoader Malware to Deploy Cobalt Strike

First seen 25 Jun 2026, 06:39 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •June 26, 2026 at 05:38 UTC

A new malware family named SharkLoader has been discovered, linked to a campaign called StrikeShark, which targets various sectors, including a diplomatic organization in Indonesia. SharkLoader acts as a loader to deploy Cobalt Strike Beacon on compromised systems. The campaign exploits vulnerabilities in internet-facing applications such as Microsoft Exchange (CVE-2021-26855), Openfire (CVE-2023-32315), and GeoServer (CVE-2024-36401). The threat actor employs both exploitation of known vulnerabilities and custom droppers disguised as legitimate software to gain initial access. The campaign has a broad geographic reach, affecting entities in multiple countries, including Taiwan, Colombia, and Lebanon. Current assessments indicate that the threat actor relies on publicly available exploits and has not been definitively attributed to any known group. The situation remains under investigation as researchers continue to analyze the scope and methods used.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 91d ago How this analysis works

Timeline

2021-03-02
CVE-2021-26855 published
Microsoft Exchange vulnerability exploited in the StrikeShark campaign, allowing unauthorized access.
Securelist
2021-03-11
CVE-2021-27076 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2022-09-30
CVE-2022-41082 added to CISA KEV
CISA flagged the vulnerability as actively exploited in the wild and added it to the Known Exploited Vulnerabilities catalog.
CISA KEV
2023-05-26
CVE-2023-32315 published
Vulnerability in Openfire exploited by the threat actor to compromise systems in Taiwan.
Gbhackers
2024-07-01
CVE-2024-36401 published
GeoServer vulnerability identified as part of the exploitation methods in the campaign.
Securelist
Recent
Discovery of SharkLoader malware
Researchers uncovered SharkLoader as part of a broader campaign affecting multiple countries and sectors.
Gbhackers

More articles in this cluster (14)

Following this threat?

Track Cobalt Strike and CVE-2021-26855 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed