Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
New Malware SharkLoader Deploys Cobalt Strike

New Malware SharkLoader Deploys Cobalt Strike

Posted on June 26, 2026 By CWS

A newly identified cyberattack operation is deploying a novel malware called SharkLoader to deliver Cobalt Strike Beacon on compromised systems. This malware campaign, tracked by Kaspersky under the alias StrikeShark, targets entities across diverse sectors and geographical locations, including diplomatic and governmental organizations.

Global Reach and Target Diversity

Kaspersky’s research indicates that the StrikeShark campaign is not limited to a specific industry or region. The campaign has affected diplomatic institutions in Indonesia, government bodies in Taiwan, and software firms in various countries. Additionally, organizations in Hong Kong, Lebanon, Syria, Colombia, North Macedonia, Nepal, and Serbia have also been targeted.

The campaign’s operators remain unidentified, but the use of tools like FScan and Pillager, often linked to Chinese-speaking developers, suggests a potential Chinese-speaking threat actor. The attack strategy employs multiple known vulnerabilities to gain initial access.

Exploitation Tactics and Malware Delivery

The attack chains exploit known vulnerabilities in Exchange Server (CVE-2021-26855), Openfire (CVE-2023-32315), and GeoServer (CVE-2024-36401) to penetrate systems. The attackers likely use publicly available exploits to achieve this. Once access is gained, they deploy web shells to establish persistence and execute a DLL side-loading chain involving “SystemSettings.exe” for SharkLoader deployment.

The StrikeShark campaign also uses custom dropper executables disguised as legitimate software like Google Update and Cisco AnyConnect. The exact method of dropper delivery remains unclear, but some employ decoy PDFs to entice users into executing the malicious files.

Technical Sophistication and Potential Goals

SharkLoader employs Perfect DLL Hijacking to load and execute malicious code, bypassing system protections like Windows Loader Lock. This involves decrypting and loading components like “DscCoreR.mui” and using Microsoft Detours library to monitor Windows API hooks. The malware also uses MinHook DLL for API hook installation, facilitating Cobalt Strike deployment.

Despite lacking built-in persistence capabilities, the malware can leverage Registry Run keys and scheduled tasks to initiate “SystemSettings.exe”. Extensive reconnaissance follows initial compromise, including Active Directory enumeration and credential theft, hinting at possible cyber espionage motives.

The absence of confirmed data exfiltration raises questions about the ultimate objectives of the StrikeShark campaign. However, the focus on government and software development sectors indicates a potential interest in political intelligence or intellectual property.

Conclusion

The StrikeShark campaign exemplifies sophisticated malware deployment across a broad range of targets, utilizing known vulnerabilities and advanced techniques. The use of SharkLoader and Cobalt Strike suggests a calculated strategy, possibly opportunistic, exploiting vulnerable systems for future operations. Ongoing vigilance and updated security measures are essential to counter such evolving cyber threats.

The Hacker News Tags:Cobalt Strike, cyber espionage, cyber threats, Cyberattack, Cybersecurity, DLL hijacking, Exchange Server, GeoServer, Information Security, Kaspersky, Malware, Openfire, SharkLoader, Vulnerabilities

Post navigation

Previous Post: New Linux Vulnerability ‘DirtyClone’ Grants Root Access
Next Post: FBI Alerts on Russian Hackers Targeting Signal Keys

Related Posts

CISA Highlights Cisco, Chrome, Arista Security Flaws CISA Highlights Cisco, Chrome, Arista Security Flaws The Hacker News
Google Identifies Three New Russian Malware Families Created by COLDRIVER Hackers Google Identifies Three New Russian Malware Families Created by COLDRIVER Hackers The Hacker News
Ivanti Warns of Active Exploitation in EPMM Vulnerability Ivanti Warns of Active Exploitation in EPMM Vulnerability The Hacker News
Self-Spreading ‘GlassWorm’ Infects VS Code Extensions in Widespread Supply Chain Attack Self-Spreading ‘GlassWorm’ Infects VS Code Extensions in Widespread Supply Chain Attack The Hacker News
NANOREMOTE Malware Uses Google Drive API for Hidden Control on Windows Systems NANOREMOTE Malware Uses Google Drive API for Hidden Control on Windows Systems The Hacker News
Your AI Agents Might Be Leaking Data — Watch this Webinar to Learn How to Stop It Your AI Agents Might Be Leaking Data — Watch this Webinar to Learn How to Stop It The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • GitHub Enhances Malware Detection Across Multiple Ecosystems
  • Anthropic Enhances Security with Claude Code Auto Mode
  • Windows 11 Vulnerabilities Expose MFA Flaws
  • HP ThinPro Encryption Flaw Risks LUKS Key Exposure
  • Gunra Ransomware Exploits VPN Vulnerabilities for Data Theft

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • GitHub Enhances Malware Detection Across Multiple Ecosystems
  • Anthropic Enhances Security with Claude Code Auto Mode
  • Windows 11 Vulnerabilities Expose MFA Flaws
  • HP ThinPro Encryption Flaw Risks LUKS Key Exposure
  • Gunra Ransomware Exploits VPN Vulnerabilities for Data Theft

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark