CiberLATAMbywhalemate

StrikeShark Targets Colombia

Kaspersky found StrikeShark, a SharkLoader campaign reaching Colombia. In Brazil, ANY.RUN reported abuse of official infrastructure.

Whalemate Labs · AI-assisted researchPublished:Updated 2 min read

Kaspersky identified StrikeShark, a new cyberattack campaign using the previously undocumented SharkLoader malware to quietly infiltrate government agencies, diplomatic entities, software development firms, and other organizations across Asia, Europe and Latin America, including Colombia.

Kaspersky identified a new cyberattack campaign called StrikeShark that uses previously undocumented malware, SharkLoader, to quietly infiltrate government agencies, diplomatic entities, software development companies, and other organizations across Asia, Europe and Latin America, including Colombia. In a parallel case, ANY.RUN detected another recent campaign, PhantomEnigma, that compromised legitimate government infrastructure in Brazil.

Which countries and organizations does StrikeShark reach?

According to Kaspersky, the operation affects government agencies in Taiwan, among others, as well as diplomatic entities, software development companies, and other organizations in Hong Kong, Lebanon, Syria, Colombia, North Macedonia, Nepal and Serbia. The company also said StrikeShark’s origin remains under investigation and that, for now, it is not attributing the campaign to any known advanced persistent threat, or APT, group.

What did PhantomEnigma do in Brazil?

According to the analysis, attackers abused .gov.br domains and official email accounts to distribute malware to [banking and public sector](/en/news/latin-america-attacks-hit-mexico) organizations. The Q2B Studio report, which cites ANY.RUN’s analysis, says Brazilian government portals and official accounts were compromised to send malicious links that appeared legitimate.

What was the goal of the compromised official infrastructure?

The goal was to reach financial and public sector targets through trusted infrastructure. In this case, the report focuses on the compromise techniques and the impact on banking and the public sector, but it does not explicitly attribute the campaign to a known APT group or a specific state actor.

What contrast do the two reports leave?

The two reports leave a clear contrast. StrikeShark has confirmed reach in Colombia and other countries in the region, but it still lacks attribution to a known group. PhantomEnigma, meanwhile, affects Brazil through compromised government infrastructure and also remains without a definitive public attribution.

Sources

View all