SharkLoader Malware Deploys Cobalt Strike Beacon Through Stealthy In-Memory Execution

Researchers have discovered a highly evasive malware loader, SharkLoader, that deploys Cobalt Strike Beacons directly into system memory.

A threat cluster known as StrikeShark is currently using this undocumented tool to breach networks across multiple industries worldwide.

By exploiting vulnerable internet-facing applications and using fake software installers, the attackers can easily establish initial access.

This campaign highlights how modern threat actors combine opportunistic vulnerability exploitation with incredibly stealthy malware delivery techniques.

StrikeShark relies on a highly flexible methodology to infiltrate enterprise networks. Instead of using a single attack vector, the group scans for and exploits known vulnerabilities in broadly used applications.

These targets include Microsoft Exchange, SharePoint, Fortinet, Cisco IOS XE, Apache Shiro, F5 BIG-IP, Hikvision, and Zimbra deployments.

Additionally, the attackers distribute custom droppers that appear to be trusted software, such as Google Update and Cisco AnyConnect installers.

Researchers assess that the group mostly uses publicly available proof-of-concept exploits rather than developing custom zero-day attacks, allowing them to cast a wide net.

SharkLoader In-Memory Beacon Attack

Once the attackers establish a foothold, SharkLoader relies heavily on DLL side-loading to remain hidden from security teams.

The malware often tricks legitimate Windows applications, like the standard system settings executable, into loading a malicious code library instead of a safe one.

Other variants use different signed Windows files to achieve the same result. By executing under the umbrella of a trusted component, SharkLoader completely avoids detection by conventional, signature-based antivirus tools.

The loader operates through multiple encrypted stages that decrypt and run entirely within the computer’s memory.

To protect the final Cobalt Strike payload, SharkLoader uses reflective loading, custom encryption routines, and packed payloads.

Researchers also observed the use of “Perfect DLL Hijacking,” a sophisticated trick that manipulates internal Windows structures to bypass standard security locks safely.

The malware further evades detection by spoofing parent processes, interfering with Windows event logging, and dynamically changing memory protections while the malicious code sleeps.

To maintain long-term access to a compromised environment, the operators set up multiple persistence mechanisms.

They configure scheduled tasks to run every 5 minutes, manipulate Windows registry keys, and create custom tasks that operate with high-level system privileges.

After securing their access, the attackers immediately begin network reconnaissance, credential theft, and Active Directory enumeration to prepare for lateral movement.

Polyswarm said, the StrikeShark campaign has successfully compromised a diverse group of targets, primarily hitting government organizations, diplomatic entities, and software development companies.

Confirmed victims span across Asia, Europe, the Middle East, and Latin America.

Indicators of Compromise (IOCs)

IOC TypeIndicatorDescription
File Hash (MD5)C559CC68986933200FD5D9E4388E2F58Malicious installer associated with the activity hunt.
File Hash (MD5)B3352B42432DEDC4A519F011DC8B5D5ACustom SharkLoader dropper hunt.

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories