Back to News
Cybercrime

New SharkLoader Malware Deploys Cobalt Strike in StrikeShark Cyberattacks

Cyber RTJune 26, 20263 min read
New SharkLoader Malware Deploys Cobalt Strike in StrikeShark Cyberattacks

A cyber attack campaign, dubbed StrikeShark by Kaspersky, is deploying a new malware, SharkLoader, to deliver Cobalt Strike Beacon. Targeting diplomatic and government organizations in Indonesia and Taiwan, among others, the campaign exploits vulnerabilities in software like Exchange Server and Openfire. Believed to be orchestrated by a Chinese-speaking actor, the attacks involve DLL hijacking and extensive reconnaissance, suggesting potential cyber espionage motives.

A recent cyber attack campaign has been identified, delivering a new malware family named SharkLoader, which functions as a loader to deploy Cobalt Strike Beacon on compromised systems. This campaign, tracked by Kaspersky under the name StrikeShark, has targeted a wide array of organizations, including a diplomatic entity in Indonesia, government bodies in Taiwan, and various software development companies across several countries. The campaign's reach extends to entities in Hong Kong, Lebanon, Syria, Colombia, North Macedonia, Nepal, and Serbia, indicating a broad geographic scope and diverse target set. Despite the extensive reach of the campaign, there are no direct links to any known threat actors or groups. However, the operators have utilized open-source post-compromise tools like FScan and Pillager, which are commonly used by Chinese-speaking developers, suggesting the involvement of a Chinese-speaking threat actor. The attack chains leverage two primary initial access pathways: exploiting known vulnerabilities in Exchange Server and Openfire, as well as a critical remote code execution bug in GeoServer. The threat actors have weaponized several remote code execution and authentication bypass vulnerabilities, including those affecting Apache Shiro, Hikvision Products, Microsoft SharePoint, Zimbra Collaboration Suite, and others. These vulnerabilities are exploited using publicly available proof-of-concept exploits hosted on platforms like GitHub, allowing the attackers to gain initial access opportunistically. Once access is gained, persistence is established through web shells and a DLL side-loading chain to deliver SharkLoader. SharkLoader is distributed using custom dropper executables that masquerade as legitimate software installers, such as Google Update and Cisco AnyConnect. These droppers execute the malware loader upon completion of the installation process. Some droppers use decoy PDF documents to entice victims to open the malicious files, although not all samples employ this technique, with some functioning solely as delivery mechanisms for SharkLoader. Once loaded, SharkLoader employs Perfect DLL Hijacking to execute malicious code while bypassing Windows Loader Lock. It decrypts and loads a component called "DscCoreR.mui," which decompresses and loads Cobalt Strike in a new thread. Additional components like SyncRes.dat and MinHook DLL install API hooks to monitor exceptions and copy the decompressed Cobalt Strike Beacon into memory, respectively, aiding in evasion of memory scanning techniques. Although SharkLoader lacks built-in persistence mechanisms, the threat actors use Registry Run keys and scheduled tasks to activate "SystemSettings.exe" upon user login or even without user login. The campaign also involves extensive reconnaissance, including Active Directory enumeration, credential theft targeting the LSASS process and NTDS database, and deploying open-source tools for scanning and information gathering. The ultimate goals of StrikeShark remain unclear, as there is no active data exfiltration observed. However, the targeting of government and software development organizations hints at a potential cyber espionage motive, possibly aimed at gathering political intelligence or intellectual property. The use of SharkLoader and Cobalt Strike, along with the exploitation of public-facing applications, suggests the attackers may also be opportunistically targeting vulnerable systems, leaving open the possibility of data exfiltration at a later stage.