Cybersecurity researchers have identified a new malware called Speagle, which hijacks the functionality and infrastructure of a legitimate program called Cobra DocGuard.

“Speagle is designed to collect sensitive information from infected computers and transmit it to a Cobra DocGuard server that has been compromised by the attackers, masking the data extraction process as legitimate client-server communication covertly ,” researchers from Symantec and Carbon Black said in a report.
Abuse of Cobra DocGuard
Cobra DocGuard is a security and encryption platform developed by EsafeNet. The misuse of this software in real-world attacks has been publicly documented twice. In January 2023, ESET documented an intrusion where a Hong Kong gaming company was compromised in September 2022 via a malicious update promoted by the software.
Later in August, Symantec uncovered activity from a new threat cluster codenamed Carderbee, which was found to be using a modified version of the program to deploy PlugX, a backdoor widely used by Chinese hacking groups such as Mustang Panda. The attacks targeted multiple organizations in Hong Kong and other Asian countries.
See also: Perseus: New Android malware "reads" your notes
Speagle: New malware threat
Speagle has not yet been linked to any hacking group. However, what makes the malware unique is that it is designed to collect and extract data only from systems that have the Cobra DocGuard data protection software installed. The activity is being tracked under the alias Runningcrab.

“This suggests deliberate targeting, possibly to facilitate intelligence gathering or industrial espionage,” Broadcom teams said. “At this time, we believe the most likely hypotheses are that this is either the work of a state actor or the work of a private contractor (for hire).”
Exactly how the malware is delivered to victims is unknown, although it may be through a supply chain attack, as evidenced by the two aforementioned cases.
Additionally, it is worth mentioning the central role played by security software and its infrastructure. Speagle not only uses a legitimate Cobra DocGuard server for command and control (C2) and as a data extraction point, but also calls a driver associated with the program to delete itself from the compromised computer.
The 32-bit .NET executable, once launched, scans the Cobra DocGuard installation folder and then proceeds to collect and transmit data from the infected machine. This includes system details and files located in specific folders, such as those containing browsing history and autofill data.
See also: Horabot Banking Trojan: New campaign focusing on Mexico
Additionally, a variant of Speagle has been found to incorporate additional functionality to enable/disable certain types of data collection, as well as to search for files related to Chinese ballistic missiles such as the Dongfeng-27 (also known as DF-27).
“Speagle is a new, parasitic threat that cleverly uses the Cobra DocGuard client to mask its malicious activity and its infrastructure to hide export traffic,” the researchers said. “Its creator undoubtedly observed previous supply chain attacksusing the software, and may have chosen it for both its perceived vulnerability and its high usage rate among targeted organizations.”

Malware protection
Static detection methods for security are not enough to avoid malware. A more robust approach should incorporate software antivirus, equipped with advanced analysis capabilities.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Information security training is also crucial. This means knowing how to recognize and avoid phishing attacks, which attackers often use to install malware.
It's also important to keep your operating system and applications up to date. These updates often include security fixes that can protect your computer from the latest threats.
See also: Interlock Ransomware: Cisco FMC Zero-Day Exploit
Also, don't forget to use firewalls and monitor network traffic to help you immediately detect suspicious activity. Users are also advised to avoid executable files downloaded from strange websites.
Finally,using strong passwords and enabling two-factor authentication can provide an extra layer of protection against malware. This can make it harder for attackers to gain access to your account , even if they manage to steal your password.
