Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
New Malware SharkLoader Deploys Cobalt Strike

New Malware SharkLoader Deploys Cobalt Strike

Posted on June 26, 2026 By CWS

A newly identified cyberattack operation is deploying a novel malware called SharkLoader to deliver Cobalt Strike Beacon on compromised systems. This malware campaign, tracked by Kaspersky under the alias StrikeShark, targets entities across diverse sectors and geographical locations, including diplomatic and governmental organizations.

Global Reach and Target Diversity

Kaspersky’s research indicates that the StrikeShark campaign is not limited to a specific industry or region. The campaign has affected diplomatic institutions in Indonesia, government bodies in Taiwan, and software firms in various countries. Additionally, organizations in Hong Kong, Lebanon, Syria, Colombia, North Macedonia, Nepal, and Serbia have also been targeted.

The campaign’s operators remain unidentified, but the use of tools like FScan and Pillager, often linked to Chinese-speaking developers, suggests a potential Chinese-speaking threat actor. The attack strategy employs multiple known vulnerabilities to gain initial access.

Exploitation Tactics and Malware Delivery

The attack chains exploit known vulnerabilities in Exchange Server (CVE-2021-26855), Openfire (CVE-2023-32315), and GeoServer (CVE-2024-36401) to penetrate systems. The attackers likely use publicly available exploits to achieve this. Once access is gained, they deploy web shells to establish persistence and execute a DLL side-loading chain involving “SystemSettings.exe” for SharkLoader deployment.

The StrikeShark campaign also uses custom dropper executables disguised as legitimate software like Google Update and Cisco AnyConnect. The exact method of dropper delivery remains unclear, but some employ decoy PDFs to entice users into executing the malicious files.

Technical Sophistication and Potential Goals

SharkLoader employs Perfect DLL Hijacking to load and execute malicious code, bypassing system protections like Windows Loader Lock. This involves decrypting and loading components like “DscCoreR.mui” and using Microsoft Detours library to monitor Windows API hooks. The malware also uses MinHook DLL for API hook installation, facilitating Cobalt Strike deployment.

Despite lacking built-in persistence capabilities, the malware can leverage Registry Run keys and scheduled tasks to initiate “SystemSettings.exe”. Extensive reconnaissance follows initial compromise, including Active Directory enumeration and credential theft, hinting at possible cyber espionage motives.

The absence of confirmed data exfiltration raises questions about the ultimate objectives of the StrikeShark campaign. However, the focus on government and software development sectors indicates a potential interest in political intelligence or intellectual property.

Conclusion

The StrikeShark campaign exemplifies sophisticated malware deployment across a broad range of targets, utilizing known vulnerabilities and advanced techniques. The use of SharkLoader and Cobalt Strike suggests a calculated strategy, possibly opportunistic, exploiting vulnerable systems for future operations. Ongoing vigilance and updated security measures are essential to counter such evolving cyber threats.

The Hacker News Tags:Cobalt Strike, cyber espionage, cyber threats, Cyberattack, Cybersecurity, DLL hijacking, Exchange Server, GeoServer, Information Security, Kaspersky, Malware, Openfire, SharkLoader, Vulnerabilities

Post navigation

Previous Post: New Linux Vulnerability ‘DirtyClone’ Grants Root Access
Next Post: FBI Alerts on Russian Hackers Targeting Signal Keys

Related Posts

China-Linked UAT-7290 Targets Telecoms with Linux Malware and ORB Nodes China-Linked UAT-7290 Targets Telecoms with Linux Malware and ORB Nodes The Hacker News
A walkthrough of the Google Workspace Password Manager A walkthrough of the Google Workspace Password Manager The Hacker News
Researchers Spot Modified Shai-Hulud Worm Testing Payload on npm Registry Researchers Spot Modified Shai-Hulud Worm Testing Payload on npm Registry The Hacker News
China-Linked Group Uses BPFDoor to Spy on Telecoms China-Linked Group Uses BPFDoor to Spy on Telecoms The Hacker News
Critical Windows Flaw Allows SYSTEM Privilege Escalation Critical Windows Flaw Allows SYSTEM Privilege Escalation The Hacker News
Helping CISOs Speak the Language of Business Helping CISOs Speak the Language of Business The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • FBI Alerts on Russian Hackers Targeting Signal Keys
  • New Malware SharkLoader Deploys Cobalt Strike
  • New Linux Vulnerability ‘DirtyClone’ Grants Root Access
  • Critical Linux Kernel Exploit Grants Root Access
  • Chinese APT Group Deploys TinyRCT in Southeast Asia

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • FBI Alerts on Russian Hackers Targeting Signal Keys
  • New Malware SharkLoader Deploys Cobalt Strike
  • New Linux Vulnerability ‘DirtyClone’ Grants Root Access
  • Critical Linux Kernel Exploit Grants Root Access
  • Chinese APT Group Deploys TinyRCT in Southeast Asia

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark