StrikeShark: investigating a new campaign delivering Cobalt Strike through SharkLoader

2026-06-24T20:51:53Z22f00144c70406397e239b1525f52c0b293dbf13d06dc6f3c619ec878252c94e
CVE-2026-3102RATStrikeSharkUEMSargamalcloud-atlascobalt-strikecontainer-securityexiftoolimage-parsingmacosmalicious-wallpapersmalwarepost-exploitationpowercloudrmmsharkloadersteam-workshopsupply-chainthreat-intelligencevbswardrivingwhatsappwifi

What happened

Kaspersky Securelist (June 2026) published multiple analyses covering active campaigns and vulnerabilities: a global “StrikeShark” campaign delivering Cobalt Strike Beacon via a custom SharkLoader loader; a WhatsApp-distributed VBScript campaign deploying a UEMS RMM agent through a multi-stage chain; dozens of malicious Steam Workshop wallpapers spreading malware (targets mainly in China and Russia); Argamal RAT distributed with infected hentai games; a wardriving assessment of Wi‑Fi hotspot security ahead of the 2026 FIFA World Cup; detailed discussion of container attack vectors and supply‑链

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
kaspersky_securelist
Record identifier
22f00144c70406397e239b1525f52c0b293dbf13d06dc6f3c619ec878252c94e
Enrichment time
2026-06-24T20:51:53Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.