SharkLoader Is Hunting Diplomats, Governments, and Developers Across Nine Countries
Kaspersky has uncovered a broad espionage campaign, according to The Hacker News, targeting diplomatic and government organisations across Indonesia, Taiwan, Hong Kong, Lebanon, Syria, Colombia, North Macedonia, Nepal, and Serbia.
The attackers, believed to be Chinese-speaking based on their tooling choices, are calling their loader SharkLoader. The campaign itself is tracked as StrikeShark. The goal is to deliver Cobalt Strike Beacon, a popular post-compromise tool that gives attackers full remote control of an infected machine.
Getting in is the first step, and the group is not picky about how. They are exploiting a long list of known vulnerabilities in widely used software including Microsoft Exchange Server, Cisco IOS XE Web UI, F5 BIG-IP, and Fortinet FortiOS, using publicly available proof-of-concept exploit code. Once inside, they plant web shells (hidden scripts on a compromised server that give attackers ongoing remote access) or disguise their malware as familiar applications like Google Update or Cisco AnyConnect.
SharkLoader then loads a chain of components that ultimately delivers Cobalt Strike into memory in a way designed to dodge security tools. One technique involves hooking the Sleep function — a standard Windows operation — to copy malicious code into memory only when a scanner is not actively looking. Think of it like a burglar who freezes the moment a security camera pans their way, then moves the moment it turns back.
No specific victim count has been published, but the campaign spans at least nine countries across four continents.
What you should do: If your organisation runs any of the software listed above, check whether all patches are current. Start with Exchange Server, Fortinet, and Cisco IOS XE. If you run web-facing software and have not reviewed your server logs recently, now is the time.
Sources

