A newly identified cyber attack campaign, tracked as StrikeShark by Kaspersky, is deploying a previously undocumented malware family called SharkLoader to deliver Cobalt Strike Beacon on compromised systems. The campaign has targeted a diplomatic organization in Indonesia, government entities in Taiwan, software development firms across multiple countries, and organizations in Hong Kong, Lebanon, Syria, Colombia, North Macedonia, Nepal, and Serbia.
Kaspersky reports that the campaign demonstrates broad geographic reach and diverse targeting rather than focusing on a specific industry or region. While no direct links to known threat actors have been established, the operators have used open-source post-compromise tools like FScan and Pillager, commonly associated with Chinese-speaking developers, suggesting a Chinese-speaking threat actor may be responsible.
Initial access is achieved through exploitation of known vulnerabilities, including CVE-2021-26855 (ProxyLogon) against Exchange Server, CVE-2023-32315 in Openfire, and CVE-2024-36401 in GeoServer. Additional exploited flaws include CVE-2016-4437 (Apache Shiro), CVE-2021-36260 (Hikvision), CVE-2021-27076 (Microsoft SharePoint), CVE-2022-27925 (Zimbra), CVE-2022-41082 (ProxyNotShell), CVE-2023-46747 (F5 BIG-IP), CVE-2024-21762 (Fortinet FortiOS), CVE-2025-55182 (React Server Components), CVE-2022-40684 (Fortinet FortiOS), and CVE-2023-20198 (Cisco IOS XE).
After gaining a foothold, attackers deploy web shells to trigger DLL side-loading via SystemSettings.exe (CVE-2021-27076) to deliver SharkLoader. Alternatively, custom droppers masquerading as legitimate software like Google Update or Cisco AnyConnect are used. SharkLoader employs Perfect DLL Hijacking to bypass Windows Loader Lock, decrypting and loading Cobalt Strike Beacon. The malware also uses Microsoft Detours and MinHook for API hooking to evade memory scanning.
Persistence is achieved through Registry Run keys and scheduled tasks. Post-compromise activities include Active Directory enumeration, credential theft targeting LSASS and NTDS, and use of tools like FScan, Searchall, and Pillager. While no active data exfiltration has been observed, the targeting suggests cyber espionage objectives, potentially for political intelligence or intellectual property theft.
CVEs: CVE-2021-26855, CVE-2023-32315, CVE-2024-36401, CVE-2016-4437, CVE-2021-36260, CVE-2021-27076, CVE-2022-27925, CVE-2022-41082, CVE-2023-46747, CVE-2024-21762, CVE-2025-55182, CVE-2022-40684
Attack groups: Chinese-speaking threat actor
Malware: SharkLoader, Cobalt Strike, FScan, Pillager, Searchall
Companies: Kaspersky, Microsoft, Google, Cisco, Apache, Hikvision, Zimbra, F5, Fortinet, Openfire, GeoServer
Products: Cobalt Strike Beacon, Microsoft Detours, MinHook, SystemSettings.exe, Google Update, Cisco AnyConnect, Exchange Server, Openfire, GeoServer, Apache Shiro, Hikvision Products, Microsoft SharePoint
Original source: thehackernews.com