logo

‘Speagle’ Malware Hijacks Security Software to Steal Missile Secrets

ID: c94d81a9-58df-53ea-8f43-96ccdecaab44

STIX ID: report--c94d81a9-58df-53ea-8f43-96ccdecaab44

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-03-23

Date Updated: 2026-04-23

Author: Ddos

...
...

**Executive summary:** Researchers from Symantec and Carbon Black discovered Infostealer.Speagle, a stealthy 32-bit .NET infostealer that parasitically abuses the Cobra DocGuard document-protection infrastructure to collect and exfiltrate browser artifacts and targeted documents (including files related to Chinese ballistic missiles), sending encrypted data via compromised legitimate Cobra DocGuard servers; the malware operates in three phases and shows indicators consistent with a supply‑chain delivery and use of a Cobra DocGuard driver to self-delete, suggesting a highly targeted, high‑sophistication espionage campaign.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.