Researchers disclosed Speagle, a newly identified infostealer that abuses the functionality and infrastructure of Cobra DocGuard, a legitimate document security product from EsafeNet. The malware exfiltrates stolen data through a compromised Cobra DocGuard server, making the traffic appear to be normal client-to-server communications and helping the activity blend in with legitimate software use. Symantec and Carbon Black said the malware is highly selective, activating its collection and exfiltration behavior only on systems where Cobra DocGuard is installed, indicating deliberate targeting rather than broad opportunistic theft.
The activity is being tracked as Runningcrab and remains unattributed, although researchers assess that the operation may support intelligence collection or industrial espionage and could be linked to a state-backed actor or a contractor-for-hire. One report said Speagle appears capable of seeking highly specific material, including documents related to Chinese ballistic missiles. Researchers have not confirmed the initial infection vector, but they noted low-confidence signs consistent with a possible supply chain compromise, echoing earlier abuse of Cobra DocGuard in prior intrusions, including attacks previously tied to Carderbee and delivery of PlugX/Korplug against organizations in Hong Kong and elsewhere in Asia.

Pull IOCs and campaign context straight into your stack.
5 events from the most recent confirmed update back to the earliest known activity.
Symantec said the initial infection vector was unconfirmed but observed indicators consistent with a possible supply-chain attack involving Cobra DocGuard. The reporting also included defensive guidance such as checking Cobra DocGuard server integrity, monitoring outbound traffic, and updating endpoint detections.
Public reporting disclosed that Speagle performs staged host and browser data collection, with at least one variant searching for files related to Chinese ballistic missile and defense topics. Researchers also found it can self-delete by abusing Cobra DocGuard's legitimate FileLock driver and a known technique for deleting a running executable.
Researchers tracked the Speagle activity under the new cluster name Runningcrab. Based on selective targeting and collection interests, they assessed the operation may be linked to state-sponsored espionage or a capable private contractor, though attribution remained unconfirmed.
Symantec and Carbon Black researchers identified a new infostealer dubbed Speagle that only operates on systems with Cobra DocGuard installed. The malware uses a compromised Cobra DocGuard server for command-and-control and to disguise data exfiltration as normal product traffic.
Before the Speagle reporting, ESET and Symantec had documented earlier incidents in which trojanized or malicious Cobra DocGuard updates were used against organizations in Hong Kong and elsewhere in Asia. These prior cases established a broader pattern of abuse involving the software.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcethehackernews.com
Open sourcesecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.