HomeSecuritySharkLoader: New malware disguises itself as Cisco and Google updates

SharkLoader: New malware disguises itself as Cisco and Google updates

A new and highly sophisticated malware has caught the attention of the cybersecurity community, as it uses techniques that make it significantly more difficult to detect by conventional protection systems. The malware, which researchers have named SharkLoader, operates as an advanced “loader,” paving the way for the installation of additional tools that allow attackers to gain complete control over compromised systems.

SharkLoader

According to PolySwarm, which analyzed the campaign, SharkLoader is not a simple loader. Instead, it is a multi-layered attack platform designed to perform most of its operations directly in the computer's memory, minimizing the traces it leaves on the disk and making it extremely difficult to detect.

Hackers exploit user trust

One of the most disturbing features of this particular campaign is the way in which the attackers manage to deceive their victims.

Instead of using obviously suspicious files, they distribute fake installers that appear as well-known applications, such as Cisco AnyConnect and Google Update . The user believes that they are installing or updating a trusted program, without realizing that they are actually running the SharkLoader installation mechanism

This technique relies on the trust that large software companies have built up over time. The more familiar an installer looks, the less likely the user is to question its authenticity.

See also: PamStealer: New Mac malware for macOS confirms passwords before "emptying" the system

Multiple ways to enter corporate networks

Researchers attribute the campaign to a monitored group called StrikeShark. However, the attackers are not limited to fake apps.

They also exploit known vulnerabilities in common enterprise platforms, such as Microsoft Exchange , SharePoint , Fortinet devices , and Cisco IOS XE . This allows them to penetrate corporate environments without the need to develop new exploits, taking advantage of organizations that are slow to install security updates .

This particular strategy significantly increases the chances of an attack being successful, as it combines social engineering techniques with the exploitation of already known weaknesses.

SharkLoader: New malware disguises itself as Cisco and Google updates

From SharkLoader to Cobalt Strike

Once installed on the system, SharkLoader takes over and delivers the Cobalt Strike Beacon, one of the most well-known tools used in post-breach attacks.

Although Cobalt Strike was originally created for legitimate security penetration testing, in recent years it has been widely used by cybercriminal groups and cyberespionage agencies, as it offers remote control, lateral movement in the network, and intelligence gathering capabilities.

According to PolySwarm, confirmed incidents have been recorded in government organizations, diplomatic missions, and software development companies in countries such as Indonesia, Taiwan, Hong Kong, Lebanon, Syria, Colombia, North Macedonia, Nepal, and Serbia.

The geographic spread suggests that the campaign is not exclusively targeting a specific organization, although the presence of multiple government and diplomatic targets raises suspicions of possible cyberespionage activity.

See also: Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Credentials

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Cloaking techniques that make detection difficult

SharkLoader utilizes advanced techniques to remain invisible even after installation. One of these is DLL Side-Loading, where it uses legitimate Windows applications, such as SystemSettings.exe, to load malicious DLLs without arousing suspicion.

It also implements Perfect DLL Hijacking techniques , allowing malicious code to be executed through trusted operating system processes. This makes it difficult for security tools that rely solely on file reputation to detect the real threat.

In addition, the malware interferes with the Event Tracing for Windows (ETW), hiding a significant part of its activity, while also falsifying parent process IDs to make it look like normal operating system operation.

SharkLoader: New malware disguises itself as Cisco and Google updates

From breach to full network control

After initial installation, attackers maintain their presence on the system through scheduled tasks, Windows registry entries, and services running with SYSTEM privileges.

They then perform network reconnaissance, collect information from Active Directory, steal credentials, extract data from the LSASS process memory, and copy the NTDS database, which contains critical information for all accounts in a corporate environment.

See also: ToddyCat: New Umbrij malware targets corporate Gmail accounts

Experts note that some of the campaign's tools appear to have been developed by Chinese developers, but there is not enough evidence to attribute the attack to any known group.

PolySwarm recommends that organizations prioritize installing all available security updates for publicly accessible services and network devices. It also recommends monitoring for suspicious DLL side-loading, memory-only processes, and other behavioral indicators, as SharkLoader is designed to bypass traditional protection solutions that rely solely on known malware signatures.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS