logo

New SharkLoader Malware Deploys Cobalt Strike in StrikeShark Cyberattacks

ID: 1a031cc7-14db-5ffd-8826-1f338ef31b7a

STIX ID: report--1a031cc7-14db-5ffd-8826-1f338ef31b7a

Feed Name: The Hacker News

Threat Score
80/100

Date Published: 2026-06-26

Date Updated: 2026-06-27

Author: [email protected] (The Hacker News)

...
...

Kaspersky observed a broad, active campaign named StrikeShark using a new loader called SharkLoader to deploy Cobalt Strike beacons against diplomatic, governmental, and private-sector targets across many countries. The attackers exploit public-facing application vulnerabilities (e.g., CVE-2021-26855, CVE-2023-32315, CVE-2024-36401), deploy web shells and malicious droppers, use DLL side-loading (Perfect DLL Hijacking) to load payloads, establish persistence via Registry Run keys and scheduled tasks, and perform extensive post-compromise reconnaissance and credential theft; attribution is tentative to a Chinese-speaking actor but no definitive group link is established.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.