StrikeShark Campaign Unleashes SharkLoader Malware to Deploy Cobalt Strike

StrikeShark Campaign Unleashes SharkLoader Malware to Deploy Cobalt Strike

First seen 25 Jun 2026, 06:39 UTC Securelistelliotonsecurity.comGbhackersFeeds2.Feedburnerwww.kaspersky.com 86% similarity 71.5
Share:

Article Content

Browse articles
ThreatCluster

A new malware family named SharkLoader has been discovered, linked to a campaign called StrikeShark, which targets various sectors, including a diplomatic organization in Indonesia. SharkLoader acts as a loader to deploy Cobalt Strike Beacon on compromised systems. The campaign exploits vulnerabilities in internet-facing applications such as Microsoft Exchange (CVE-2021-26855), Openfire (CVE-2023-32315), and GeoServer (CVE-2024-36401). The threat actor employs both exploitation of known vulnerabilities and custom droppers disguised as legitimate software to gain initial access. The campaign has a broad geographic reach, affecting entities in multiple countries, including Taiwan, Colombia, and Lebanon. Current assessments indicate that the threat actor relies on publicly available exploits and has not been definitively attributed to any known group. The situation remains under investigation as researchers continue to analyze the scope and methods used.

Key Points: • SharkLoader malware serves as a loader for deploying Cobalt Strike Beacon. • The campaign exploits multiple vulnerabilities, including CVE-2021-26855 and CVE-2023-32315. • Affected sectors include diplomatic organizations and software companies across various countries.

ThreatCluster AI

Timeline

2021-03-02
CVE-2021-26855 published
Microsoft Exchange vulnerability exploited in the StrikeShark campaign, allowing unauthorized access.
Securelist
2021-03-11
CVE-2021-27076 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2022-09-30
CVE-2022-41082 added to CISA KEV
CISA flagged the vulnerability as actively exploited in the wild and added it to the Known Exploited Vulnerabilities catalog.
CISA KEV
2023-05-26
CVE-2023-32315 published
Vulnerability in Openfire exploited by the threat actor to compromise systems in Taiwan.
Gbhackers
2024-07-01
CVE-2024-36401 published
GeoServer vulnerability identified as part of the exploitation methods in the campaign.
Securelist
Recent
Discovery of SharkLoader malware
Researchers uncovered SharkLoader as part of a broader campaign affecting multiple countries and sectors.
Gbhackers

Community

Browse all →