CiberLATAMbywhalemate

StrikeShark Targets Colombia

Kaspersky found StrikeShark, a SharkLoader campaign reaching Colombia. In Brazil, ANY.RUN reported abuse of official infrastructure.

Whalemate Labs · AI-assisted researchPublished:2 min read

Kaspersky identified StrikeShark, a new cyberattack campaign using the previously undocumented SharkLoader malware to quietly infiltrate government agencies, diplomatic entities, software development firms, and other organizations across Asia, Europe and Latin America, including Colombia.

StrikeShark under investigation

Kaspersky has identified a new cyberattack campaign called StrikeShark, which uses previously undocumented malware named SharkLoader to quietly infiltrate government agencies, diplomatic entities, software development firms, and other organizations across Asia, Europe and Latin America, including Colombia.

According to Kaspersky, the operation has affected government agencies in Taiwan, along with diplomatic entities, software development firms and other organizations in Hong Kong, Lebanon, Syria, Colombia, North Macedonia, Nepal and Serbia. The company also said the origin of StrikeShark is still under investigation and that, for now, it is not attributing the campaign to any known Advanced Persistent Threat, or APT, group.

Brazil, official infrastructure abused

In parallel, ANY.RUN detected another recent campaign, called PhantomEnigma, that compromised legitimate government infrastructure in Brazil. According to that analysis, attackers abused .gov.br domains and official email accounts to distribute malware to banking and public sector organizations.

The Q2B Studio report, which cites ANY.RUN's analysis, says Brazilian government portals and official accounts were compromised to send malicious links that appeared legitimate. The goal was to reach financial and public sector targets through that trusted infrastructure.

In this case, the report focuses on the compromise techniques and the impact on banking and the public sector, but it does not explicitly attribute the campaign to a known APT group or a specific state actor.

Open attribution cases

The two reports leave a clear contrast. StrikeShark has confirmed reach in Colombia and other countries in the region, but it still has no attribution to a known group. PhantomEnigma, meanwhile, affects Brazil through compromised government infrastructure and also remains without a definitive public attribution.

Sources

View all