CVE Tools

New SharkLoader Malware Deploys Cobalt Strike in StrikeShark Cyberattacks

The Hacker NewsBy The Hacker News

PoC publicMicrosoft SharePointZimbra Collaboration Suite

Our summary

A newly identified campaign dubbed StrikeShark distributes the previously unknown Windows malware family SharkLoader, which then deploys Cobalt Strike Beacon on compromised systems. Kaspersky reports targeting includes organizations in Indonesia, Taiwan, and multiple other countries, using publicly available post-compromise tools and opportunistic exploitation of exposed services. The initial access leverages vulnerabilities such as ProxyLogon (CVE-2021-26855), Openfire traversal flaws (CVE-2023-32315), and GeoServer remote code execution (CVE-2024-36401), highlighting an elevated risk of espionage and follow-on payload delivery.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store