Security News

Cybersecurity news aggregator

CRITICAL Attacks SC Media

New SharkLoader malware campaign deploys Cobalt Strike Beacon

The newly identified SharkLoader malware campaign gains initial access by exploiting critical vulnerabilities in Microsoft Exchange Server (CVE-2021-26855, CVSS 9.1), Openfire (CVE-2023-32315, CVSS 8.6), and GeoServer (CVE-2024-36401, CVSS 9.8). Affected versions include Exchange Server 2013 and 2016, Openfire 3.10.0 to 4.6.7 and 4.7.0 to 4.7.4, and GeoServer versions prior to 2.22.6, 2.23.6, 2.24.4, and 2.25.2. Once deployed via web shells or droppers, SharkLoader uses Perfect DLL Hijacking to load Cobalt Strike Beacon, enabling reconnaissance, credential theft, and lateral movement for potential espionage or data theft.
Read Full Article →

Malware New SharkLoader malware campaign deploys Cobalt Strike Beacon June 29, 2026 Share By SC Staff As noted by The Hacker News, a newly discovered cyberattack campaign, dubbed StrikeShark by Kaspersky, is deploying a previously undocumented malware family called SharkLoader. This malware serves as a loader for Cobalt Strike Beacon on compromised hosts. The StrikeShark campaign exhibits a broad geographic reach, targeting a diplomatic organization in Indonesia, government entities in Taiwan, software development companies globally, and other sectors in Hong Kong, Lebanon, Syria, Colombia, North Macedonia, Nepal, and Serbia. While no direct links to known threat actors exist, the use of open-source tools like FScan and Pillager suggests a Chinese-speaking threat actor. Initial access is gained through exploitation of vulnerabilities in Exchange Server (CVE-2021-26855), Openfire (CVE-2023-32315), and GeoServer (CVE-2024-36401), among others. SharkLoader is delivered via web shells or custom dropper executables disguised as legitimate software. It employs Perfect DLL Hijacking to bypass Windows Loader Lock, ultimately decrypting and loading Cobalt Strike Beacon. Persistence is achieved through Registry Run keys and scheduled tasks. The campaign includes extensive reconnaissance, Active Directory enumeration, and credential theft. The ultimate goals remain unclear, but the targeting suggests potential cyber espionage for political intelligence or intellectual property, or opportunistic targeting of vulnerable systems. Source: The Hacker News SC Staff Related Malware Grand Theft Auto VI hype fuels new wave of scams targeting gamers SC Staff June 26, 2026 Security firms Malwarebytes and NordVPN have identified a surge of sophisticated fake websites offering "VIP Early Access" to Grand Theft Auto VI. Malware New ‘Edgecution’ malware uses browser extension to deploy ransomware SC Staff June 25, 2026 The Edgecution malware exploits the Chrome Native Messaging protocol to enable communication between browser extensions and native desktop applications. Malware StealC infrastructure takedown assisted by AI analysis, C2 infiltration Laura French June 25, 2026 Microsoft, Proofpoint, IBM, Europol and other partners took aim the StealC and Amadey “assembly line.” Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Adware You can skip this ad in 5 seconds

Share this article