Researchers identified a previously undocumented malware family, SharkLoader, during an intrusion affecting a diplomatic organization in Indonesia and linked it to a broader campaign tracked as StrikeShark. The loader was used to deliver Cobalt Strike Beacon after attackers exploited internet-facing applications including Microsoft Exchange, SharePoint, Openfire, and GeoServer, and also through custom droppers disguised as legitimate software such as Google Update and Cisco AnyConnect. Victims spanned government, diplomatic, software development, and other sectors in Indonesia, Taiwan, Hong Kong, Lebanon, Syria, Colombia, North Macedonia, Nepal, Serbia, and additional countries, suggesting broad and partly opportunistic targeting.
SharkLoader used DLL sideloading, encrypted multi-stage modules, reflective loading, API hooking, ETW suppression, PPID spoofing, and memory-protection changes to evade detection while launching Beacon in memory. The operators established persistence with scheduled tasks and registry Run keys, then carried out reconnaissance, Active Directory enumeration, and credential dumping with tools including FScan, Searchall, Pillager, SharpGPOAbuse, Procdump64, and ntdsutil. Researchers said attribution remains preliminary, but the use of several open-source tools associated with Chinese-speaking developers led to a low-confidence assessment that the campaign was conducted by a Chinese-speaking threat actor.

Pull IOCs and campaign context straight into your stack.
2 events from the most recent confirmed update back to the earliest known activity.
Based on the use of several open-source tools associated with Chinese-speaking developers, researchers assessed with low confidence that StrikeShark is a Chinese-speaking threat actor. The attribution was described as preliminary.
During an investigation into activity affecting a diplomatic organization in Indonesia, researchers identified a previously undocumented malware family named SharkLoader and tracked the broader intrusion cluster as StrikeShark. They found the campaign used exploitation of internet-facing applications and custom droppers to deliver Cobalt Strike Beacon across multiple countries and sectors.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 14 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
11 references tracked. Mallory keeps watching after this page renders.
hkcert.org
Open sourcecybersecuritynews.com
Open sourceblog.polyswarm.io
Open sourcescworld.com
Open sourcecommunity.gurucul.com
Open sourcemalware.news
Open sourceelliotonsecurity.com
Open sourcesecurelist.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.