New ‘Speagle’ Malware Hijacks Cobra DocGuard to Steal Sensitive Data via Compromised Servers
The newly identified infostealer malware, Speagle, poses a significant threat to organizations utilizing Cobra DocGuard, a document security platform. Developed by EsafeNet, Cobra DocGuard has been compromised by Speagle, which leverages the platform for…
The newly identified infostealer malware, Speagle, poses a significant threat to organizations utilizing Cobra DocGuard, a document security platform. Developed by EsafeNet, Cobra DocGuard has been compromised by Speagle, which leverages the platform for data theft.
Speagle is designed to integrate seamlessly into its host environment, exploiting the software it targets for data exfiltration. Unlike conventional malware, Speagle focuses on acquiring documents related to sensitive topics, such as Chinese ballistic missile systems.
Cobra DocGuard has a history of security breaches. In September 2022, it was involved in a supply chain attack targeting a Hong Kong-based gambling company. In August 2023, the Carderbee group utilized it to deploy the Korplug backdoor, affecting various organizations in Hong Kong and Asia.
Symantec analysts have classified Speagle as a 32-bit .NET executable that functions only when Cobra DocGuard is installed. The responsible threat actor, Runningcrab, has no confirmed connections with known groups. Research suggests potential state sponsorship or private contractor involvement due to the malware's selective targeting and operational sophistication.
The malware's infection vector remains unconfirmed, with indications of a supply chain attack. Speagle employs a legitimate Cobra DocGuard driver, the FileLock driver, to self-delete post-operation, a technique using the SetFileInformationByHandle() API.
The newly identified infostealer malware, Speagle, poses a significant threat to organizations utilizing Cobra DocGuard, a document security platform.
Runningcrab hijacked a Cobra DocGuard server for command-and-control, masking data exfiltration as regular network traffic. This strategy highlights the actor's resources and preexisting knowledge of the victim's infrastructure.
Speagle initiates data collection by verifying Cobra DocGuard installation through specific registry keys. The process includes:
Phase 1: Gathering machine details and Cobra DocGuard client identifiers. If no valid ID is located, Speagle self-deletes. Phase 2: Executing Windows Management Instrumentation queries to collect detailed system information. Phase 3: Targeting browser data, including history and bookmarks, particularly from Chromium-based browsers.
Some Speagle variants specifically search for documents using Chinese-language keywords related to defense technologies.
Collected data is compressed using the Deflate algorithm, encrypted with AES-128, and transmitted via HTTP POST requests to a compromised Cobra DocGuard server.
Organizations using Cobra DocGuard should audit outbound network traffic for connections to IP addresses 60.30.147[.]18 and 222.222.254[.]165 . Endpoint detection tools must be updated to identify Speagle's known SHA-256 hashes. Verification of Cobra DocGuard server integrity and review of software update channels is advised to prevent unauthorized modifications.
Based on reporting by Cyber Security News.
