SharkLoader Malware Deploys Cobalt Strike via DLL Hijacking in StrikeShark Campaign
Kaspersky has documented a new threat cluster called StrikeShark deploying a previously undocumented loader named SharkLoader to deliver Cobalt Strike Beacon across government entities, software developers and diplomatic organisations in Lebanon, Syria, Taiwan, Indonesia and beyond.

Computer terminal displaying network connection logs representing the SharkLoader StrikeShark Cobalt Strike malware campaign targeting government and technology organisations in 2026
Kaspersky has documented a previously undiscovered malware family called SharkLoader, operating as a loader for Cobalt Strike Beacon within a wider threat cluster the vendor tracks as StrikeShark. The campaign has targeted a diplomatic organisation in Indonesia, government entities in Taiwan, software development companies across multiple countries, and organisations in Hong Kong, Lebanon, Syria, Colombia, North Macedonia, Nepal, and Serbia. Lebanon and Syria's presence in the victim list places this campaign within the threat landscape facing MENA-adjacent organisations and merits monitoring by GCC security teams tracking regional state-sponsored activity.
The campaign has not been attributed to a named threat actor. However, Kaspersky assessed with moderate confidence that the operators are Chinese-speaking, based on the use of open-source post-compromise tools FScan and Pillager that are commonly associated with Chinese-speaking developers. No direct links to known Chinese APT groups have been established.
Initial Access Methods
StrikeShark operators used multiple known vulnerabilities for initial access across different targets. The Indonesian diplomatic entity was compromised through ProxyLogon (CVE-2021-26855). Taiwanese software developers were targeted via a path traversal flaw in Openfire (CVE-2023-32315). A Colombian organisation was hit via a critical RCE in GeoServer (CVE-2024-36401). The full list of weaponised vulnerabilities also includes flaws in Apache Shiro, Hikvision Products, Microsoft SharePoint, Zimbra Collaboration Suite, F5 BIG-IP, Fortinet FortiOS, React Server Components, and Cisco IOS XE.
The breadth of the vulnerability list is a signal of opportunistic targeting methodology rather than tailored spear operations. Kaspersky assessed that the actors are likely using publicly available proof-of-concept exploits from GitHub and other open-source platforms to gain initial access wherever vulnerable systems are exposed.
How SharkLoader Works
After gaining a foothold, the operators achieve persistence by deploying web shells that trigger a DLL side-loading chain using a legitimate Microsoft executable (SystemSettings.exe via CVE-2021-27076) to load the malicious SharkLoader DLL. A second delivery method uses custom dropper executables masquerading as legitimate software installers including Google Update and Cisco AnyConnect, with some samples also using decoy PDF documents to encourage the victim to open the malicious file.
Once loaded, SharkLoader implements Perfect DLL Hijacking, a technique documented by researcher Elliot Killick, to execute malicious code while bypassing Windows Loader Lock. The DLL decrypts and loads a component called DscCoreR.mui, which decompresses and loads Cobalt Strike Beacon in a suspended thread alongside two supporting components: SyncRes.dat, which installs Windows API hooks via the Microsoft Detours library to monitor runtime exceptions, and a MinHook DLL that hooks VirtualAlloc and Sleep functions to copy the decompressed Cobalt Strike shellcode into allocated memory.
After the API hooks are installed and the shellcode written to the thread buffer, SharkLoader calls the ResumeThread API to start Cobalt Strike execution. The loader does not include built-in persistence, relying instead on Registry Run keys and scheduled tasks to reactivate SystemSettings.exe at login or even without a logged-in user session.
Post-Compromise Activity
Following initial compromise and persistence, the operators conducted extensive reconnaissance including Active Directory enumeration, credential theft targeting the LSASS process and NTDS database file, and open-source scanner deployment including FScan, Searchall, and Pillager. No confirmed data exfiltration has been observed, though Kaspersky noted that Cobalt Strike's file operation and data exfiltration modules could be employed at a later stage.
The targeting of government entities and software developers, combined with the absence of confirmed data theft, suggests a cyber espionage orientation with interest in political intelligence or intellectual property rather than financially motivated activity.
Why GCC Teams Should Monitor This
The presence of Lebanese and Syrian targets, combined with the opportunistic vulnerability exploitation methodology, means that any GCC enterprise running unpatched versions of the listed products, particularly Fortinet FortiOS, Cisco IOS XE, F5 BIG-IP, Microsoft Exchange, or Zimbra, should review exposure. The FortiBleed campaign that compromised over 430,000 FortiGate devices globally earlier this month demonstrates the scale of opportunistic exploitation possible when these systems go unpatched. StrikeShark adds to the list of active campaigns scanning for the same vulnerability classes.
Omar Al-Hakeem
Senior Cyber Threat Analyst | MENA RegionOmar Al-Hakeem is a cybersecurity researcher specializing in threat intelligence, ransomware trends, and nation-state activity across the Middle East and North Africa. With over 12 years of experience in SOC operations and incident response, he provides deep technical breakdowns of emerging attacks and regional cyber risks. At MENA Cyber Wire, Omar focuses on real-world threat analysis and actionable defense strategies for enterprises and startups.