Threadlinqs IntelligenceStart free

Threat actorChinaTracked since 2026-07

StrikeShark

As of 2026-07-11, StrikeShark is a China-nexus threat actor tracked by Threadlinqs Intelligence across 2 threats spanning malware. ATT&CK coverage spans 43 techniques across 13 tactics in 2 of 2 tracked threats. Most-observed techniques: T1003 (OS Credential Dumping), T1005 (Data from Local System), T1016 (System Network Configuration Discovery).

Tracked threats
22 high
First seen
2026-07-03
Last seen
2026-07-11
ATT&CK techniques
43across 2 of 2 threats
Related CVEs
13Referenced by its activity
Attribution
ChinaNation or origin
Nation: China · 2 tracked threat(s) · Categories: MALWARE

Activity timeline

StrikeShark appears in 2 tracked threats between and .

ATT&CK techniques observed

43 techniques observed across 2 of 2 tracked threats · Discovery (11), Stealth (formerly Defense Evasion) (9), Execution (5), Privilege Escalation (4), Resource Development (4), Command and Control (3)
  • T1003 OS Credential Dumping — Credential Accessobserved in 2 of 2 tracked threats
  • T1005 Data from Local System — Collectionobserved in 2 of 2 tracked threats
  • T1016 System Network Configuration Discovery — Discoveryobserved in 2 of 2 tracked threats
  • T1021 Remote Services — Lateral Movementobserved in 2 of 2 tracked threats
  • T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 2 of 2 tracked threats
  • T1033 System Owner/User Discovery — Discoveryobserved in 2 of 2 tracked threats
  • T1036 Masquerading — Stealth (formerly Defense Evasion)observed in 2 of 2 tracked threats
  • T1053 Scheduled Task/Job — Persistenceobserved in 2 of 2 tracked threats
  • T1055 Process Injection — Privilege Escalationobserved in 2 of 2 tracked threats
  • T1059 Command and Scripting Interpreter — Executionobserved in 2 of 2 tracked threats
  • T1069 Permission Groups Discovery — Discoveryobserved in 2 of 2 tracked threats
  • T1071 Application Layer Protocol — Command and Controlobserved in 2 of 2 tracked threats
  • T1082 System Information Discovery — Discoveryobserved in 2 of 2 tracked threats
  • T1087 Account Discovery — Discoveryobserved in 2 of 2 tracked threats
  • T1105 Ingress Tool Transfer — Command and Controlobserved in 2 of 2 tracked threats

Tracked threats

Related CVEs

13 CVEs referenced by tracked StrikeShark activity