Kaspersky Uncovers StrikeShark Cyberattack Campaign in LATAM
By Diego Valverde | Journalist & Industry Analyst -
Tue, 07/28/2026 - 13:30
Kaspersky researchers have identified StrikeShark, a cyberattack campaign targeting government agencies, diplomatic entities, and software companies across Latin America, Asia, and the European Union. The operation relies on a previously undocumented malware called SharkLoader, which uses advanced evasion techniques to deploy Cobalt Strike Beacon and establish persistent access to compromised systems.
A newly identified cyberattack campaign is targeting organizations across Latin America, Asia, and the European Union with a previously undocumented malware designed to evade detection and establish long-term access to compromised networks. Researchers at Kaspersky say the operation, dubbed StrikeShark, has affected government agencies, diplomatic entities, software development companies, and other organizations, highlighting the continued evolution of advanced cyber threats.
According to Kaspersky's Global Research and Analysis Team (GReAT), the campaign leverages a custom malware known as SharkLoader. While the company continues to investigate the operation, researchers have not attributed it to any known advanced persistent threat (APT) group.
The campaign has targeted organizations in multiple countries, including diplomatic entities in Indonesia, government agencies in Taiwan, and software development companies and other organizations in Hong Kong, Lebanon, Syria, Colombia, North Macedonia, Nepal, and Serbia.
StrikeShark Campaing Specifications
StrikeShark relies on several initial compromise methods, allowing attackers to adapt their approach depending on the target's environment. Researchers found evidence of attackers exploiting vulnerabilities in internet-facing applications, including Microsoft Exchange, Microsoft SharePoint, and Openfire servers.
In other cases, the attackers distributed malicious droppers disguised as legitimate software, such as Google Update installers or Cisco AnyConnect applications. Some samples also used PDF documents as lures, prompting victims to unknowingly install the malware.
Once inside a system, SharkLoader employs multiple techniques designed to remain undetected. The malware uses DLL side-loading, which abuses legitimate Windows applications to load encrypted malicious modules without raising security alerts. Those modules then decrypt and execute additional components while installing API hooks that modify operating system functions to bypass detection mechanisms.
The final stage of the attack deploys Cobalt Strike Beacon, a legitimate penetration testing tool that is frequently misused by cybercriminals. Once installed, the tool enables attackers to communicate with compromised systems, move laterally across networks, conduct reconnaissance and extract sensitive information.
The combination of legitimate administrative tools with custom-developed malware reflects a growing trend in sophisticated cyber operations, where attackers blend widely available offensive frameworks with proprietary code to reduce the likelihood of detection.
Security Hygiene Remains Critical
"The StrikeShark campaign reflects the evolution of the threat landscape, where cybercriminals combine widely available attack tools with custom-developed malware and sophisticated techniques to evade detection mechanisms," says María Isabel Manjarrez, Security Researcher for Latin America, Kaspersky's Global Research and Analysis Team.
She also notes that the use of lures disguised as legitimate software, together with the exploitation of known vulnerabilities, underscores the importance of maintaining rigorous security patch management, implementing robust endpoint detection, and response solutions, and strengthening employee awareness to identify and prevent these threats.
The campaign also reinforces the importance of addressing known vulnerabilities before attackers can exploit them. Many of the techniques identified by Kaspersky rely on unpatched internet-facing systems, making vulnerability management a key component of enterprise cyber resilience.
To reduce exposure to StrikeShark and similar attacks, Kaspersky recommends that organizations keep operating systems and applications fully updated to remediate known vulnerabilities. The company also advises deploying security solutions capable of detecting and blocking malicious droppers before they compromise endpoints.
Employee awareness remains another critical layer of defense. Continuous cybersecurity training can help organizations reduce the success of social engineering techniques commonly used to distribute malicious files or convince users to install compromised software. Kaspersky also recommends protecting corporate endpoints with integrated security platforms capable of detecting threats during the earliest stages of an attack.
In addition, the company advises organizations to strengthen their defenses with threat intelligence services that provide actionable visibility into emerging attack campaigns, allowing security teams to identify new threats earlier and make more informed security decisions.




