logo

Mystery hackers use novel SharkLoader dropper against governments, software devs

ID: 4d14cf40-524a-5ef2-afcb-c4c6e5ef32ac

STIX ID: report--4d14cf40-524a-5ef2-afcb-c4c6e5ef32ac

Feed Name: Help Net Security

Threat Score
75/100

Date Published: 2026-06-26

Date Updated: 2026-06-26

Author: Zeljka Zorz

...
...

Kaspersky uncovered the StrikeShark campaign where attackers deploy a novel dropper called SharkLoader—delivered via exploitation of publicly known vulnerabilities and fake installers—to install Cobalt Strike beacons, perform credential harvesting, reconnaissance and lateral movement across government and software development targets in multiple countries while employing stealth and log-tampering to evade detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.