<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/new-sharkloader-malware-deploys-cobalt-strike-in-strikeshark-cyberattacks-xcgemyzvk" -->

---
title: New SharkLoader Malware Deploys Cobalt Strike in...
description: Kaspersky has identified a new cyberattack campaign called StrikeShark that uses a previously undocumented malware loader, SharkLoader, to deploy Cobalt Strike...
canonical: https://daily.dev/posts/new-sharkloader-malware-deploys-cobalt-strike-in-strikeshark-cyberattacks-xcgemyzvk
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: New SharkLoader Malware Deploys Cobalt Strike in StrikeShark Cyberattacks | daily.dev
og:description: Kaspersky has identified a new cyberattack campaign called StrikeShark that uses a previously undocumented malware loader, SharkLoader, to deploy Cobalt Strike...
og:url: https://daily.dev/posts/new-sharkloader-malware-deploys-cobalt-strike-in-strikeshark-cyberattacks-xcgemyzvk
og:image: https://api.daily.dev/og/posts/XCgEmyZVK.png
og:image:alt: New SharkLoader Malware Deploys Cobalt Strike in StrikeShark Cyberattacks
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# New SharkLoader Malware Deploys Cobalt Strike in StrikeShark Cyberattacks

**[Security Boulevard](https://daily.dev/sources/securityboulevard)** · 5 min read · 0 upvotes · 0 comments

## Summary

Kaspersky has identified a new cyberattack campaign called StrikeShark that uses a previously undocumented malware loader, SharkLoader, to deploy Cobalt Strike Beacon on compromised systems. Targets include government and diplomatic organizations across Asia, the Middle East, and Latin America, as well as software development companies globally. Attackers gained initial access by exploiting known vulnerabilities in Microsoft Exchange, Openfire, GeoServer, and other public-facing applications using publicly available proof-of-concept exploits. Post-compromise activity includes DLL side-loading, web shell deployment, in-memory Beacon execution, Active Directory enumeration, and credential theft targeting LSASS and NTDS. The campaign is attributed with moderate confidence to a Chinese-speaking threat actor. No confirmed data exfiltration has been observed, but the targeting pattern suggests cyber espionage objectives. CISOs are advised to patch exposed systems, hunt for SharkLoader and Cobalt Strike behavioral indicators, and review identity exposure after any suspected compromise.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://securityboulevard.com/2026/06/new-sharkloader-malware-deploys-cobalt-strike-in-strikeshark-cyberattacks>

## Similar posts on daily.dev

- [StrikeShark: a new campaign involving a custom SharkLoader and Cobalt Strike Beacon](https://daily.dev/posts/strikeshark-a-new-campaign-involving-a-custom-sharkloader-and-cobalt-strike-beacon-u7eag9vxh) · Securelist · 0 upvotes · 0 comments
- [Silver Dragon Targets Organizations in Southeast Asia and Europe](https://daily.dev/posts/silver-dragon-targets-organizations-in-southeast-asia-and-europe-svwipmebu) · Check Point Research · 0 upvotes · 0 comments
- [CountLoader Broadens Russian Ransomware Operations With Multi-Version Malware Loader](https://daily.dev/posts/countloader-broadens-russian-ransomware-operations-with-multi-version-malware-loader-df0hp16ec) · The Hacker News · 0 upvotes · 0 comments
- [Stealth in Layers: Unmasking the Loader used in Targeted Email Campaigns](https://daily.dev/posts/stealth-in-layers-unmasking-the-loader-used-in-targeted-email-campaigns-xfgpoq8c1) · Cyble · 0 upvotes · 0 comments

---

Tags: [#malware](https://daily.dev/tags/malware)

[View this post on daily.dev](https://daily.dev/posts/new-sharkloader-malware-deploys-cobalt-strike-in-strikeshark-cyberattacks-xcgemyzvk)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"New SharkLoader Malware Deploys Cobalt Strike in StrikeShark Cyberattacks","url":"https://daily.dev/posts/new-sharkloader-malware-deploys-cobalt-strike-in-strikeshark-cyberattacks-xcgemyzvk","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/new-sharkloader-malware-deploys-cobalt-strike-in-strikeshark-cyberattacks-xcgemyzvk"},"datePublished":"2026-06-29T10:00:18.071Z","dateModified":"2026-06-29T10:00:49.882Z","description":"Kaspersky has identified a new cyberattack campaign called StrikeShark that uses a previously undocumented malware loader, SharkLoader, to deploy Cobalt Strike...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/8fe9eeb967de205fd6743e2535f16178?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/8fe9eeb967de205fd6743e2535f16178?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Security Boulevard","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Security Boulevard","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/3613c832180040de8d85bb29f74395be","url":"https://daily.dev/sources/securityboulevard"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/new-sharkloader-malware-deploys-cobalt-strike-in-strikeshark-cyberattacks-xcgemyzvk","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"malware","timeRequired":"PT5M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Security Boulevard","item":"https://daily.dev/sources/securityboulevard"},{"@type":"ListItem","position":3,"name":"New SharkLoader Malware Deploys Cobalt Strike in StrikeShark Cyberattacks"}]}
```

