Hackers Use Cisco AnyConnect and Google Update Lures to Drop SharkLoader Malware
ID: cdf05fdc-e557-5359-a4e5-9ca259656e8d
STIX ID: report--cdf05fdc-e557-5359-a4e5-9ca259656e8d
Feed Name: cybersecurityNews.com
StrikeShark is an active malware campaign that uses convincing fake installers to deploy a custom loader called SharkLoader, which performs DLL sideloading and in-memory decryption to run a Cobalt Strike Beacon; the campaign exploits known enterprise vulnerabilities, targets governments and software firms across multiple countries, performs credential dumping and AD hash extraction, evades detection via API and event logging hooks, and includes a set of MD5 hashes, domains, filenames, and other IoCs for detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
