VMTech
Discuss a project

StrikeShark: SharkLoader deploys Cobalt Strike

StrikeShark: SharkLoader deploys Cobalt Strike

Colleagues in cybersecurity: the StrikeShark campaign was observed — a new SharkLoader deploys Cobalt Strike.

Summary:
- Victims: diplomatic mission in Indonesia, government agencies in Taiwan, software firms, others.
- Initial access: exploitation of public vulnerabilities (Exchange, Openfire, GeoServer, etc.) and fake installers/droppers.
- Technique: web shells, Perfect DLL Hijacking, side‑loading SystemSettings.dll, persistence via registry and Task Scheduler.
- Post‑compromise: credential harvesting/exfiltration, use of FScan and Pillager.

Why it matters: public PoCs + loader + Cobalt Strike accelerate compromise and lateral movement.

Is your infrastructure ready to withstand such attack chains?

#cybersecurity #incidents #ThreatIntel #vulnerability

Open analytics
On the site 5 views
min read 1 29.06.2026
On Instagram 2 views
On Instagram 1 reach
Instagram

StrikeShark: SharkLoader deploys Cobalt Strike

Open the post on Instagram ↗