CyberSecurityBoardThreat Intel · CVEs · Products
Malware

StrikeShark Campaign Uses Novel SharkLoader Malware to Deploy Cobalt Strike Beacon

June 26, 2026

A newly identified cyber attack campaign, tracked as StrikeShark by Kaspersky, is deploying a previously undocumented malware family called SharkLoader to deliver Cobalt Strike Beacon on compromised systems. The campaign has targeted a diplomatic organization in Indonesia, government entities in Taiwan, software development firms across multiple countries, and organizations in Hong Kong, Lebanon, Syria, Colombia, North Macedonia, Nepal, and Serbia.

Kaspersky reports that the campaign demonstrates broad geographic reach and diverse targeting rather than focusing on a specific industry or region. While no direct links to known threat actors have been established, the operators have used open-source post-compromise tools like FScan and Pillager, commonly associated with Chinese-speaking developers, suggesting a Chinese-speaking threat actor may be responsible.

Initial access is achieved through exploitation of known vulnerabilities, including CVE-2021-26855 (ProxyLogon) against Exchange Server, CVE-2023-32315 in Openfire, and CVE-2024-36401 in GeoServer. Additional exploited flaws include CVE-2016-4437 (Apache Shiro), CVE-2021-36260 (Hikvision), CVE-2021-27076 (Microsoft SharePoint), CVE-2022-27925 (Zimbra), CVE-2022-41082 (ProxyNotShell), CVE-2023-46747 (F5 BIG-IP), CVE-2024-21762 (Fortinet FortiOS), CVE-2025-55182 (React Server Components), CVE-2022-40684 (Fortinet FortiOS), and CVE-2023-20198 (Cisco IOS XE).

After gaining a foothold, attackers deploy web shells to trigger DLL side-loading via SystemSettings.exe (CVE-2021-27076) to deliver SharkLoader. Alternatively, custom droppers masquerading as legitimate software like Google Update or Cisco AnyConnect are used. SharkLoader employs Perfect DLL Hijacking to bypass Windows Loader Lock, decrypting and loading Cobalt Strike Beacon. The malware also uses Microsoft Detours and MinHook for API hooking to evade memory scanning.

Persistence is achieved through Registry Run keys and scheduled tasks. Post-compromise activities include Active Directory enumeration, credential theft targeting LSASS and NTDS, and use of tools like FScan, Searchall, and Pillager. While no active data exfiltration has been observed, the targeting suggests cyber espionage objectives, potentially for political intelligence or intellectual property theft.

CVEs: CVE-2021-26855, CVE-2023-32315, CVE-2024-36401, CVE-2016-4437, CVE-2021-36260, CVE-2021-27076, CVE-2022-27925, CVE-2022-41082, CVE-2023-46747, CVE-2024-21762, CVE-2025-55182, CVE-2022-40684

Attack groups: Chinese-speaking threat actor

Malware: SharkLoader, Cobalt Strike, FScan, Pillager, Searchall

Companies: Kaspersky, Microsoft, Google, Cisco, Apache, Hikvision, Zimbra, F5, Fortinet, Openfire, GeoServer

Products: Cobalt Strike Beacon, Microsoft Detours, MinHook, SystemSettings.exe, Google Update, Cisco AnyConnect, Exchange Server, Openfire, GeoServer, Apache Shiro, Hikvision Products, Microsoft SharePoint