Speagle Malware Hijacks Cobra DocGuard to Steal Data
Key Takeaways A new information-stealing malware, Speagle, has been identified, specifically targeting organizations using EsafeNet’s Cobra DocGuard platform. Speagle is designed to exfiltrate...
Key Takeaways
- A new information-stealing malware, Speagle, has been identified, specifically targeting organizations using EsafeNet’s Cobra DocGuard platform.
- Speagle is designed to exfiltrate highly sensitive data, including documents related to Chinese ballistic missile technology, by masquerading as legitimate software.
- The threat actor, dubbed Runningcrab, is highly sophisticated, leveraging compromised Cobra DocGuard servers for command-and-control and using the platform’s own drivers for self-deletion.
- The infection vector is suspected to be a supply chain attack, highlighting the critical need for robust software supply chain security.
A sophisticated new infostealer malware, dubbed Speagle, is actively compromising organizations that rely on Cobra DocGuard, a document security and encryption platform developed by Chinese firm EsafeNet. This threat, detailed in a recent analysis, is engineered to blend seamlessly into its target environment, leveraging the very software it aims to exploit as a cover for its covert data exfiltration operations. Speagle’s capabilities extend beyond generic system information theft, specifically seeking out and stealing files related to highly sensitive topics, including documents concerning Chinese ballistic missiles.
Table Of Content
Cobra DocGuard has a documented history of security vulnerabilities and exploitation. In September 2022, the platform was implicated in a supply chain attack that targeted a gambling enterprise in Hong Kong. Later, in August 2023, the threat group known as Carderbee exploited Cobra DocGuard to deploy the Korplug backdoor, also identified as PlugX, against various organizations across Hong Kong and other parts of Asia. This recurring pattern underscores Cobra DocGuard’s consistent appeal to attackers who view it as a trusted, widely deployed entry point into victim networks.
Analysts at Symantec identified Speagle as a 32-bit .NET executable that only fully activates its malicious payload on systems where Cobra DocGuard is present. The actor behind this campaign has been designated Runningcrab, although no definitive links to any previously known threat groups have been established. Researchers postulate that the actor is likely either state-sponsored or a highly skilled private contractor, a conclusion drawn from the malware’s precise targeting of Cobra DocGuard users and its specific focus on defense-related documentation.
While the exact infection vector remains unconfirmed, initial evidence points towards a possible supply chain attack. Speagle employs a legitimate Cobra DocGuard driver, specifically the FileLock driver, to remove itself from the compromised system once its operations are complete. This behavior is consistent with Trojanized software updates. The self-deletion mechanism utilizes the SetFileInformationByHandle() API to rename and then delete the running executable, a technique previously discovered by security researcher Jonas Lykkegaard. The use of the platform’s own driver for self-removal strongly suggests that the attacker possesses intimate knowledge of Cobra DocGuard’s internal architecture.
Further demonstrating its sophistication, Runningcrab has been observed hijacking a legitimate Cobra DocGuard server belonging to the targeted organization. This compromised server then served as the command-and-control (C2) infrastructure for the malware. By routing exfiltrated data through a server that the victim organization regularly communicates with, the attacker effectively camouflaged the malicious traffic, making it appear entirely normal. This level of meticulous planning indicates a well-resourced actor with prior reconnaissance and understanding of the victim’s network environment.
How Speagle Collects and Exfiltrates Stolen Data
Upon verifying the installation of Cobra DocGuard through specific Windows registry keys under the Esafenet CDG System path, Speagle initiates a methodical, multi-stage data collection process.
Phase 1: Initial Reconnaissance
The first phase involves gathering fundamental system information, including the machine’s username, hostname, and unique Cobra DocGuard client identifiers found in local configuration files. Should the malware fail to locate a valid client ID, it immediately triggers its self-deletion routine and terminates without attempting any data theft.
Phase 2: System and Network Mapping
In the second phase, Speagle executes Windows Management Instrumentation (WMI) queries to collect detailed information about active processes, network connections, installed services, scheduled tasks, and firewall rules. Concurrently, it maps files and folders across all connected drives, constructing a comprehensive overview of the compromised machine’s contents.
Phase 3: Browser Data Exfiltration
The third phase targets sensitive browser data. Speagle extracts browsing history, autofill entries, downloaded files, bookmarks, and search shortcuts from directories associated with Chromium-based browsers.
One identified variant of Speagle possesses enhanced capabilities, specifically scanning for documents containing Chinese-language keywords related to defense technology. These keywords translate to terms such as “ballistic missile,” “hypersonic,” “warhead,” “Dongfeng,” and “Changjian,” directly referencing specific Chinese missile systems, including the Dongfeng-27.

After each data collection phase, Speagle compresses the gathered information using the Deflate algorithm, encrypts it with AES-128 in CBC mode, and then transmits it via HTTP POST requests to a hardcoded, compromised Cobra DocGuard server.
What You Should Do
- Immediately audit outbound network traffic for any unexpected connections to the IP addresses
60.30.147[.]18and222.222.254[.]165. - Update endpoint detection and response (EDR) tools to identify and flag Speagle’s four known SHA-256 file hashes.
- Verify the integrity of all Cobra DocGuard server installations within your environment.
- Scrutinize software update channels for Cobra DocGuard for any signs of unauthorized modifications or suspicious activity.
- Apply the latest endpoint protection signatures and ensure all security software is up-to-date.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.