StrikeShark
Reports
3
First seen
Jun 24, 2026
Last seen
Jul 10, 2026
Motivation
Espionage, Financial
Relationships
Filled ◆ = CVE exploited in the wild. Entities that appear together in Signalis reporting — co-mention, not confirmed collaboration. Reports naming many actors at once (weekly roundups) are excluded from relationship edges.
Top ATT&CK techniques
T1190 Exploit Public-Facing Application ×3T1055 Process Injection ×2T1105 Ingress Tool Transfer ×1T1003.003 OS Credential Dumping - NTDS ×1T1003 OS Credential Dumping ×1T1053.005 Scheduled Task/Job - Scheduled Task ×1T1047 Windows Management Instrumentation ×1T1087.002 Account Discovery - Domain Account ×1T1071 Application Layer Protocol ×1T1021 Remote Services ×1T1218.011 System Binary Proxy Execution - Rundll32 ×1T1133 External Remote Services ×1
Indicators
cve ×45filename ×17hash_md5 ×9domain ×4registry_key ×1
Indicator values are available on Pro and via the API.
Associated CVEs
CVE-2016-4437 (exploited)CVE-2021-26855 (exploited)CVE-2021-27076 (exploited)CVE-2021-36260 (exploited)CVE-2022-27925 (exploited)CVE-2022-41082 (exploited)CVE-2023-32315 (exploited)CVE-2023-46747 (exploited)CVE-2024-21762 (exploited)CVE-2024-36401 (exploited)CVE-2026-25939 (exploited)CVE-2026-35616 (exploited)CVE-2021-27137 (exploited)CVE-2026-50751 (exploited)CVE-2025-55182 (exploited)CVE-2022-40684 (exploited)CVE-2026-21509 (exploited)CVE-2023-20198 (exploited)CVE-2026-21513 (exploited)