logo

Hackers Use Fake Cisco AnyConnect and Google Update Installers to Drop SharkLoader

ID: 5ee54b27-e075-5bb0-9307-28f787ff4e27

STIX ID: report--5ee54b27-e075-5bb0-9307-28f787ff4e27

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-07-03

Date Updated: 2026-07-03

Author: Tushar Subhra Dutta

...
...

**SharkLoader campaign:** Researchers uncovered SharkLoader, a sophisticated loader used to deliver Cobalt Strike and follow-on tools across government, diplomatic, and software targets in multiple countries; the attackers use fake installers and exploitation of internet-facing vulnerabilities, employ DLL sideloading and in-memory execution to evade detection, and perform credential theft, AD enumeration, LSASS dumping and lateral movement — defenders are advised to patch exposed services, hunt for DLL side-loading and in-memory activity, and monitor behavioral indicators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.