By Interestana AI Editorial — AI-drafted, human-overseen. How we report
SharkLoader Malware Deploys Cobalt Strike in Cyberattacks
A new malware family named SharkLoader has been identified as the primary loader for deploying Cobalt Strike Beacon in a recently observed cyberattack campaign. Cybersecurity firm Kaspersky is tracking this activity under the designation StrikeShark. The campaign has specifically targeted a diplomatic organization located in Indonesia and government organizations in Taiwan. This discovery marks the first instance of SharkLoader being utilized in such attacks.
The SharkLoader malware is designed to establish persistence on compromised systems and then download and execute additional payloads. In the observed StrikeShark campaign, the subsequent payload deployed is Cobalt Strike Beacon, a legitimate penetration testing tool that is frequently abused by malicious actors for post-exploitation activities. This allows attackers to gain deeper access and control over the victim's network.
Kaspersky's analysis indicates that the initial infection vector for SharkLoader is likely through malicious email attachments. These attachments, when opened by unsuspecting users, initiate the deployment of the SharkLoader malware. The sophistication of this attack lies in its use of a previously unknown loader to facilitate the deployment of a well-known and powerful post-exploitation framework, highlighting an evolving threat landscape.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.