Close Menu
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    • Blogging
    • SEO & Digital Marketing
    • WiFi / Internet & Networking
    • Cybersecurity
    • Tech Tools & Mobile / Apps
    • Privacy & Online Earning
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    Home»Cybersecurity»Speagle Malware Hijacks Cobra DocGuard to Steal Data via Compromised Servers
    Cybersecurity

    Speagle Malware Hijacks Cobra DocGuard to Steal Data via Compromised Servers

    adminBy adminMarch 19, 2026No Comments3 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    Speagle Malware Hijacks Cobra DocGuard to Steal Data via Compromised Servers
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananMar 19, 2026Cyber Espionage / Threat Intelligence

    Cybersecurity researchers have flagged a new malware dubbed Speagle that hijacks the functionality and infrastructure of a legitimate program called Cobra DocGuard.

    “Speagle is designed to surreptitiously harvest sensitive information from infected computers and transmit it to a Cobra DocGuard server that has been compromised by the attackers, masking the data exfiltration process as legitimate communications between client and server,” Symantec and Carbon Black researchers said in a report published today.

    Cobra DocGuard is a document security and encryption platform developed by EsafeNet. The abuse of this software in real-world attacks has been publicly recorded twice to date. In January 2023, ESET documented an intrusion where a gambling company in Hong Kong was compromised in September 2022 via a malicious update pushed by the software.

    Later that August, Symantec highlighted the activity of a new threat cluster codenamed Carderbee, which was found using a trojanized version of the program to deploy PlugX, a backdoor widely used by Chinese hacking groups like Mustang Panda. The attacks targeted multiple organizations in Hong Kong and other Asian countries.

    Speagle remains unattributed to date. But what makes the malware noteworthy is that it’s designed to gather and exfiltrate data from only those systems that have the Cobra DocGuard data protection software installed. The activity is being tracked under the moniker Runningcrab.

    “This indicates deliberate targeting, possibly to facilitate intelligence collection or industrial espionage,” the Broadcom-owned threat hunting teams said. “At present, we believe the most likely hypotheses are that it is either the work of a state-sponsored actor or the work of a private contractor available for hire.”

    Exactly how the malware is delivered to victims is unknown, although it’s suspected that it may have been done via a supply chain attack, as evidenced by the two aforementioned cases. 

    In addition, the central role played by the security software and its infrastructure deserves a mention. Not only does Speagle use a legitimate Cobra DocGuard server for command-and-control (C2) and as a data exfiltration point, it also invokes a driver associated with the program to delete itself from the compromised host.

    The 32-bit .NET executable, once launched, first checks the installation folder of Cobra DocGuard and then proceeds to harvest and transmit data from the infected machine in phases. This includes details about the system and files located in specific folders, such as those that contain web browser history and autofill data.

    What’s more, one variant of Speagle has been found to incorporate additional functionality to turn on/off certain types of data collection, as well as search for files related to Chinese ballistic missiles like Dongfeng-27 (aka DF-27).

    “Speagle is a novel, parasitic threat that cleverly makes use of Cobra DocGuard’s client to mask its malicious activity and its infrastructure to hide exfiltration traffic,” researchers said. “Its developer no doubt took notice of previous supply chain attacks using the software and may have selected it both for its perceived vulnerability and its high rate of use among targeted organizations.”

    Cobra Compromised data DocGuard hijacks Malware Servers Speagle steal
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleGoogle Chat 2026.03.09.882868461.Release APK Download by Google LLC
    Next Article Nile adds microsegmentation and native NAC to its secure NaaS platform
    admin
    • Website

    Related Posts

    Google expands Data Manager API with GMP event ingestion

    June 2, 2026

    Google AI Overview Data Looks Different For Commercial Queries

    May 30, 2026

    Position 1 Is Halfway Down The Page: New SERP Visibility Data

    May 29, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Search Blog
    About
    About

    At WifiPortal.tech, we share simple, easy-to-follow guides on cybersecurity, online privacy, and digital opportunities. Our goal is to help everyday users browse safely, protect personal data, and explore smart ways to earn online. Whether you’re new to the digital world or looking to strengthen your online knowledge, our content is here to keep you informed and secure.

    Trending Blogs

    Netskope introduces AI Command Center to monitor and secure enterprise AI sprawl

    June 2, 2026

    How to Do Prompt-Based Keyword Research to Show Up Better in AI Results

    June 2, 2026

    How SEO turns customer success into AI-readable proof

    June 2, 2026

    How to get your website indexed by Google

    June 2, 2026
    Categories
    • Blogging (88)
    • Cybersecurity (1,955)
    • Privacy & Online Earning (230)
    • SEO & Digital Marketing (1,342)
    • Tech Tools & Mobile / Apps (1,796)
    • WiFi / Internet & Networking (326)

    Subscribe to Updates

    Stay updated with the latest tips on cybersecurity, online privacy, and digital opportunities straight to your inbox.

    WifiPortal.tech is a blogging platform focused on cybersecurity, online privacy, and digital opportunities. We share easy-to-follow guides, tips, and resources to help you stay safe online and explore new ways of working in the digital world.

    Our Picks

    Netskope introduces AI Command Center to monitor and secure enterprise AI sprawl

    June 2, 2026

    How to Do Prompt-Based Keyword Research to Show Up Better in AI Results

    June 2, 2026

    How SEO turns customer success into AI-readable proof

    June 2, 2026
    Most Popular
    • Netskope introduces AI Command Center to monitor and secure enterprise AI sprawl
    • How to Do Prompt-Based Keyword Research to Show Up Better in AI Results
    • How SEO turns customer success into AI-readable proof
    • How to get your website indexed by Google
    • The 50 Most-Cited Websites in Gemini (June 2026)
    • Cisco brings agentic ops platform and security overhaul to Cisco Live
    • Google’s May Core Update Complete After Volatile Rollout
    • How a ‘client brain’ gives AI the context SEO work needs
    © 2026 WifiPortal.tech. Designed by WifiPortal.tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.