Back to Intel

Intel Node

StrikeShark: investigating a new campaign delivering Cobalt Strike through SharkLoader

mediumapt2026-06-24T10:00:03+00:00source excerpt
aptmalwarevulnerabilitycve

Source excerpt · The upstream feed supplied only part of this article.Read the original source →

Kaspersky researchers analyze a new global campaign dubbed StrikeShark that delivers Cobalt Strike Beacon via custom SharkLoader malware.

Introduction During our research of activity affecting a diplomatic organization in Indonesia, we uncovered a previously undocumented malware family that we have named SharkLoader . What initially appeared to be an isolated case quickly expanded into a broader campaign as we identified additional SharkLoader infections across multiple countries and sectors. Our investigation revealed that SharkLoader serves as a loader designed to deploy Cobalt Strike Beacon on compromised systems.

We observed the threat actor deploying SharkLoader through exploitation of internet-facing applications, including Microsoft Exchange, Microsoft SharePoint, and Openfire Server, as well as through malware-based delivery mechanisms.

Read Original Source