Kaspersky researchers have uncovered a previously undocumented malware campaign called StrikeShark, which uses a custom loader named SharkLoader to deploy Cobalt Strike Beacon on compromised systems. Initial access is gained through exploitation of vulnerabilities in internet-facing applications (Microsoft Exchange ProxyLogon, Openfire, GeoServer, Fortinet, Cisco, and others) as well as dropper executables disguised as legitimate software like Google Update and Cisco AnyConnect. SharkLoader employs DLL sideloading via a legitimate Windows binary (SystemSettings.exe), uses 'Perfect DLL Hijacking' to bypass the Windows loader lock, and deploys multiple API hooks via Microsoft Detours and MinHook to evade memory scanning. The Cobalt Strike Beacon is encrypted with Blowfish and AES, reflectively loaded in memory, and executed in a suspended thread. Post-compromise activity includes Active Directory enumeration, credential dumping from LSASS and NTDS, and use of open-source tools (FScan, Searchall, Pillager) associated with Chinese-speaking developers. Victims span government entities, diplomatic organizations, and software development companies across Indonesia, Taiwan, Lebanon, Syria, Hong Kong, Colombia, and more. Attribution remains preliminary with low confidence pointing to a Chinese-speaking threat actor.

20m read timeFrom securelist.com
Post cover image
Table of contents
IntroductionInitial infectionSharkLoader installationSharkLoader DLL – Main implantDscCoreR.mui and SyncRes.dat DLLsPersistence mechanismPost-compromise activityVictimologyAttributionConclusionIndicators of compromise
159 Impressions