Public Exploits Now Feed a Custom Cobalt Strike Loader

The break is no longer a single product flaw. StrikeShark now looks like a broad access campaign that reuses public web-app exploits to get in, then hands the foothold to SharkLoader so Cobalt Strike can stay on the network and move beyond the first compromised host. Kaspersky ties the activity to a custom loader that deploys Cobalt Strike Beacon and to opportunistic abuse of many internet-facing vulnerabilities across Microsoft Exchange, Openfire, GeoServer, Fortinet FortiOS, F5 BIG-IP, Cisco IOS XE, Zimbra, Apache Shiro, and Hikvision. The set includes older flaws such as CVE-2021-26855, CVE-2023-32315, and CVE-2024-36401, and the campaign uses publicly available proof-of-concept exploits rather than bespoke zero-days. The practical change is the blast radius. Any exposed admin or app service can become the same intrusion path, so patching one named CVE does not remove the campaign pattern once a reachable service is left open.

Part of the PlainSec briefing for 2026-06-27

Sources