# StrikeShark

> As of 2026-07-11, StrikeShark is a China-nexus threat actor tracked by Threadlinqs Intelligence across 2 threats spanning malware. ATT&CK coverage spans 43 techniques across 13 tactics in 2 of 2 tracked threats. Most-observed techniques: T1003 (OS Credential Dumping), T1005 (Data from Local System), T1016 (System Network Configuration Discovery).

- **Nation:** China
- **Tracked threats:** 2
- **Categories:** MALWARE
- **As of:** 2026-07-11

## ATT&CK techniques observed

43 techniques observed across 2 of 2 tracked threats. Tactics: Discovery (11), Stealth (formerly Defense Evasion) (9), Execution (5), Privilege Escalation (4), Resource Development (4), Command and Control (3).

- [T1003](https://intel.threadlinqs.com/technique/T1003) OS Credential Dumping — Credential Access — observed in 2 of 2 tracked threats
- [T1005](https://intel.threadlinqs.com/technique/T1005) Data from Local System — Collection — observed in 2 of 2 tracked threats
- [T1016](https://intel.threadlinqs.com/technique/T1016) System Network Configuration Discovery — Discovery — observed in 2 of 2 tracked threats
- [T1021](https://intel.threadlinqs.com/technique/T1021) Remote Services — Lateral Movement — observed in 2 of 2 tracked threats
- [T1027](https://intel.threadlinqs.com/technique/T1027) Obfuscated Files or Information — Stealth (formerly Defense Evasion) — observed in 2 of 2 tracked threats
- [T1033](https://intel.threadlinqs.com/technique/T1033) System Owner/User Discovery — Discovery — observed in 2 of 2 tracked threats
- [T1036](https://intel.threadlinqs.com/technique/T1036) Masquerading — Stealth (formerly Defense Evasion) — observed in 2 of 2 tracked threats
- [T1053](https://intel.threadlinqs.com/technique/T1053) Scheduled Task/Job — Persistence — observed in 2 of 2 tracked threats
- [T1055](https://intel.threadlinqs.com/technique/T1055) Process Injection — Privilege Escalation — observed in 2 of 2 tracked threats
- [T1059](https://intel.threadlinqs.com/technique/T1059) Command and Scripting Interpreter — Execution — observed in 2 of 2 tracked threats
- [T1069](https://intel.threadlinqs.com/technique/T1069) Permission Groups Discovery — Discovery — observed in 2 of 2 tracked threats
- [T1071](https://intel.threadlinqs.com/technique/T1071) Application Layer Protocol — Command and Control — observed in 2 of 2 tracked threats
- [T1082](https://intel.threadlinqs.com/technique/T1082) System Information Discovery — Discovery — observed in 2 of 2 tracked threats
- [T1087](https://intel.threadlinqs.com/technique/T1087) Account Discovery — Discovery — observed in 2 of 2 tracked threats
- [T1105](https://intel.threadlinqs.com/technique/T1105) Ingress Tool Transfer — Command and Control — observed in 2 of 2 tracked threats

## Tracked threats

- [StrikeShark Campaign: SharkLoader Dropper Targets Governments and Software Developers via N-Day Exploits and Trojanized Installers to Deploy Cobalt Strike](https://intel.threadlinqs.com/threat/TL-2026-1237) — HIGH
- [SharkLoader Malware Campaign Uses Fake Cisco AnyConnect and Google Update Installers to Deploy Cobalt Strike](https://intel.threadlinqs.com/threat/TL-2026-1101) — HIGH

## Related CVEs

13 CVEs referenced by tracked StrikeShark activity.

- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2024-36401](https://intel.threadlinqs.com/cve/CVE-2024-36401)
- [CVE-2024-21762](https://intel.threadlinqs.com/cve/CVE-2024-21762)
- [CVE-2023-46747](https://intel.threadlinqs.com/cve/CVE-2023-46747)
- [CVE-2023-32315](https://intel.threadlinqs.com/cve/CVE-2023-32315)
- [CVE-2023-20198](https://intel.threadlinqs.com/cve/CVE-2023-20198)
- [CVE-2022-41082](https://intel.threadlinqs.com/cve/CVE-2022-41082)
- [CVE-2022-40684](https://intel.threadlinqs.com/cve/CVE-2022-40684)
- [CVE-2022-27925](https://intel.threadlinqs.com/cve/CVE-2022-27925)
- [CVE-2021-36260](https://intel.threadlinqs.com/cve/CVE-2021-36260)
- [CVE-2021-27076](https://intel.threadlinqs.com/cve/CVE-2021-27076)
- [CVE-2021-26855](https://intel.threadlinqs.com/cve/CVE-2021-26855)
- [CVE-2016-4437](https://intel.threadlinqs.com/cve/CVE-2016-4437)

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/StrikeShark
