SharkLoader Drops Cobalt Strike on Asian Government Targets in 'StrikeShark' Campaign

A previously undocumented loader is being used against a diplomatic office in Indonesia and government bodies in Taiwan, with operators staging Cobalt Strike Beacon as the final payload.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 3 min read
SharkLoader Drops Cobalt Strike on Asian Government Targets in 'StrikeShark' Campaign
Share

Key points

  • SharkLoader is a newly documented malware loader deploying Cobalt Strike Beacon against government targets in Asia.
  • Kaspersky, tracking the activity as StrikeShark, has confirmed victims at a diplomatic organization in Indonesia and government organizations in Taiwan.
  • The choice of a bespoke loader, rather than an off-the-shelf alternative, suggests deliberate evasion of specific defences.
  • No initial access vector, persistence mechanism or C2 infrastructure details have been published.
  • Hashes and network indicators tied to StrikeShark have not been broadly circulated at time of writing.

A new loader family called SharkLoader is being used to plant Cobalt Strike Beacon on targeted government networks across Southeast and East Asia, according to Kaspersky, which is tracking the activity as StrikeShark.

The targeting is narrow. Known victims are a diplomatic organization in Indonesia and government organizations in Taiwan. That profile is consistent with espionage rather than commodity crimeware, though Kaspersky has not published attribution. Our earlier story on Operation Dragon Weave, from 1 June 2026, documented a separate campaign hitting Taiwanese government targets with a different C2 framework, so the region is drawing sustained attention.

What does SharkLoader actually do?

SharkLoader functions as a stager: its job is to pull down and execute Cobalt Strike Beacon on a compromised host. Cobalt Strike is a commercial penetration-testing tool whose cracked and leaked builds have become a fixture of intrusion sets for years. Defenders should treat any Beacon callout as a full-host compromise until proven otherwise.

The decision to ship a bespoke loader is itself informative. Threat actors who build a custom delivery component rather than reaching for open-source shellcode loaders generally do so to defeat EDR (endpoint detection and response) or YARA (pattern-matching malware detection) coverage they have already tested against. That implies pre-engagement reconnaissance of the target's tooling, or at minimum a desire for longer dwell time than commodity loaders provide.

Should you worry?

If your organisation operates in diplomatic or government environments in the region, yes. For everyone else, the tradecraft is worth understanding.

Hunt for Beacon. Named-pipe patterns and the well-documented stager URI conventions are still catching real intrusions. Beacon's process-injection behaviors leave artifacts in memory that EDR memory scanners pick up reliably when policies are tuned for detection rather than prevention-only mode.

Review egress from government environments to low-reputation hosting. StrikeShark's victimology suggests the operators are willing to burn infrastructure on small numbers of high-value targets, which usually means short-lived VPS (virtual private server) C2 nodes.

Treat any new loader family as a deliberate signal. SharkLoader is the visible piece. The more consequential question is what the operators are doing post-Beacon: credential theft, lateral movement to mail systems, or staging for longer-term implants. None of that will appear in loader telemetry.

Kaspersky has not, as of publication, named individual researchers on the StrikeShark write-up. Expect indicators of compromise to firm up as more victims are identified. The Kaspersky writeup remains the primary reference for teams mapping telemetry from the affected regions.

© 2026 Threat Vectr