logo

New Malware Targets Users of Cobra DocGuard Software

ID: 63299f4f-49eb-5d7d-a61c-0a9c8bf8cb95

STIX ID: report--63299f4f-49eb-5d7d-a61c-0a9c8bf8cb95

Feed Name: security.com

Threat Score
85/100

Date Published: 2026-03-19

Date Updated: 2026-04-29

Author: Threat Hunter Team

...
...

Symantec/Carbon Black discovered Infostealer.Speagle, a 32-bit .NET infostealer that parasitically leverages the legitimate Cobra DocGuard client and a compromised Cobra server to collect and exfiltrate sensitive files (including searches for Chinese ballistic missile–related documents). The report describes multi-phase collection (WMI, filesystem, browser artifacts), AES-128/CBC encrypted exfiltration over HTTP to hardcoded Cobra-server URLs, self-deletion using a Cobra driver, multiple sample hashes and C2 IPs, and assesses a likely high-target espionage motive with possible supply-chain delivery and attribution to a named actor, Runningcrab.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.