New SharkLoader Malware Deploys Cobalt Strike in StrikeShark Cyberattacks
PoC publicMicrosoft SharePointZimbra Collaboration SuiteOur summary
A newly identified campaign dubbed StrikeShark distributes the previously unknown Windows malware family SharkLoader, which then deploys Cobalt Strike Beacon on compromised systems. Kaspersky reports targeting includes organizations in Indonesia, Taiwan, and multiple other countries, using publicly available post-compromise tools and opportunistic exploitation of exposed services. The initial access leverages vulnerabilities such as ProxyLogon (CVE-2021-26855), Openfire traversal flaws (CVE-2023-32315), and GeoServer remote code execution (CVE-2024-36401), highlighting an elevated risk of espionage and follow-on payload delivery.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.