Runningcrab is an unattributed threat activity cluster associated with the Speagle malware family, a selective information-stealing tool that abuses the legitimate Cobra DocGuard document security platform for command-and-control, data collection, and covert exfiltration. The operation is notable for targeting systems where Cobra DocGuard is installed and blending malicious traffic with normal client-server communications of that software, indicating a tailored and operationally aware intrusion set. Speagle is a 32-bit .NET malware family designed to harvest system information and collect files from selected locations, including data associated with browser history and autofill artifacts. Variants have included configurable collection behavior, and at least one sample searched for material related to the DF-27 ballistic missile, consistent with intelligence-gathering or industrial espionage objectives. The malware also uses a legitimate driver associated with Cobra DocGuard to remove itself from infected hosts, demonstrating defense-evasion tradecraft. Runningcrab has not been publicly attributed to a specific named actor. Available reporting has assessed that the operation may be linked to a state-sponsored actor or a contractor conducting espionage-oriented collection, based on its narrow victimology, selective targeting, and focus on sensitive data theft rather than disruptive or monetization-driven outcomes. The initial access vector has not been confirmed, though supply-chain compromise has been considered a plausible delivery mechanism because of the broader history of malicious abuse involving Cobra DocGuard in attacks affecting organizations in Hong Kong and elsewhere in Asia. Known associated malware: Speagle.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.