Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

New ‘Speagle’ Malware Hijacks Cobra DocGuard to Steal Sensitive Data via Compromised Servers

The newly identified infostealer malware, Speagle, poses a significant threat to organizations utilizing Cobra DocGuard, a document security platform. Developed by EsafeNet, Cobra DocGuard has been compromised by Speagle, which leverages the platform for…

The newly identified infostealer malware, Speagle, poses a significant threat to organizations utilizing Cobra DocGuard, a document security platform. Developed by EsafeNet, Cobra DocGuard has been compromised by Speagle, which leverages the platform for data theft.

Speagle is designed to integrate seamlessly into its host environment, exploiting the software it targets for data exfiltration. Unlike conventional malware, Speagle focuses on acquiring documents related to sensitive topics, such as Chinese ballistic missile systems.

Cobra DocGuard has a history of security breaches. In September 2022, it was involved in a supply chain attack targeting a Hong Kong-based gambling company. In August 2023, the Carderbee group utilized it to deploy the Korplug backdoor, affecting various organizations in Hong Kong and Asia.

Symantec analysts have classified Speagle as a 32-bit .NET executable that functions only when Cobra DocGuard is installed. The responsible threat actor, Runningcrab, has no confirmed connections with known groups. Research suggests potential state sponsorship or private contractor involvement due to the malware's selective targeting and operational sophistication.

The malware's infection vector remains unconfirmed, with indications of a supply chain attack. Speagle employs a legitimate Cobra DocGuard driver, the FileLock driver, to self-delete post-operation, a technique using the SetFileInformationByHandle() API.

The newly identified infostealer malware, Speagle, poses a significant threat to organizations utilizing Cobra DocGuard, a document security platform.
Heather Lyons · Thehackingpost

Runningcrab hijacked a Cobra DocGuard server for command-and-control, masking data exfiltration as regular network traffic. This strategy highlights the actor's resources and preexisting knowledge of the victim's infrastructure.

Speagle initiates data collection by verifying Cobra DocGuard installation through specific registry keys. The process includes:

Phase 1: Gathering machine details and Cobra DocGuard client identifiers. If no valid ID is located, Speagle self-deletes. Phase 2: Executing Windows Management Instrumentation queries to collect detailed system information. Phase 3: Targeting browser data, including history and bookmarks, particularly from Chromium-based browsers.

Some Speagle variants specifically search for documents using Chinese-language keywords related to defense technologies.

Advertisement

Collected data is compressed using the Deflate algorithm, encrypted with AES-128, and transmitted via HTTP POST requests to a compromised Cobra DocGuard server.

Organizations using Cobra DocGuard should audit outbound network traffic for connections to IP addresses 60.30.147[.]18 and 222.222.254[.]165 . Endpoint detection tools must be updated to identify Speagle's known SHA-256 hashes. Verification of Cobra DocGuard server integrity and review of software update channels is advised to prevent unauthorized modifications.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories