New SharkLoader Malware Deploys Cobalt Strike in StrikeShark Cyberattacks
ID: 1a031cc7-14db-5ffd-8826-1f338ef31b7a
STIX ID: report--1a031cc7-14db-5ffd-8826-1f338ef31b7a
Feed Name: The Hacker News
Kaspersky observed a broad, active campaign named StrikeShark using a new loader called SharkLoader to deploy Cobalt Strike beacons against diplomatic, governmental, and private-sector targets across many countries. The attackers exploit public-facing application vulnerabilities (e.g., CVE-2021-26855, CVE-2023-32315, CVE-2024-36401), deploy web shells and malicious droppers, use DLL side-loading (Perfect DLL Hijacking) to load payloads, establish persistence via Registry Run keys and scheduled tasks, and perform extensive post-compromise reconnaissance and credential theft; attribution is tentative to a Chinese-speaking actor but no definitive group link is established.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
