Securelist StrikeShark Campaign Unleashes SharkLoader Malware to Deploy Cobalt Strike
Article Content
- •SharkLoader malware serves as a loader for deploying Cobalt Strike Beacon.
- •The campaign exploits multiple vulnerabilities, including CVE-2021-26855 and CVE-2023-32315.
- •Affected sectors include diplomatic organizations and software companies across various countries.
A new malware family named SharkLoader has been discovered, linked to a campaign called StrikeShark, which targets various sectors, including a diplomatic organization in Indonesia. SharkLoader acts as a loader to deploy Cobalt Strike Beacon on compromised systems. The campaign exploits vulnerabilities in internet-facing applications such as Microsoft Exchange (CVE-2021-26855), Openfire (CVE-2023-32315), and GeoServer (CVE-2024-36401). The threat actor employs both exploitation of known vulnerabilities and custom droppers disguised as legitimate software to gain initial access. The campaign has a broad geographic reach, affecting entities in multiple countries, including Taiwan, Colombia, and Lebanon. Current assessments indicate that the threat actor relies on publicly available exploits and has not been definitively attributed to any known group. The situation remains under investigation as researchers continue to analyze the scope and methods used.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (14)
Following this threat?
Track Cobalt Strike and CVE-2021-26855 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
FamousSparrow Deploys SparroWocky Backdoor in Latin America The China-aligned cyberespionage group FamousSparrow has replaced its previous backdoor, SparrowDoor, with a new malware called SparroWocky, targeting governmental organizations in Latin America since August 2025. ESET Research attributes this campaign to a likely response to increased U.S. interests in the region.…
Cisco Talos Launches CAIRN to Combat AI-Integrated Malware On September 22, 2026, Cisco Talos released CAIRN, an open-source toolkit designed to hunt, classify, and track AI-integrated malware. The first documented malware analyzed with CAIRN is CLOSEDQUORUM, a Windows implant that autonomously delegates command-and-control decisions to commercial large language models…