logo

Speagle Malware Hijacks Cobra DocGuard to Steal Data via Compromised Servers

ID: f3f12dfc-b39f-52b6-a7dc-9e44d12a9a1e

STIX ID: report--f3f12dfc-b39f-52b6-a7dc-9e44d12a9a1e

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2026-03-19

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Researchers have identified 'Speagle', a novel malware that hijacks the Cobra DocGuard client and infrastructure to surreptitiously harvest and exfiltrate sensitive data from only systems running that software. Tracked as 'Runningcrab', Speagle likely leverages supply-chain techniques, uses legitimate DocGuard servers for C2 and exfiltration, can toggle collection features, searches for specific sensitive files (including Chinese missile-related documents), and may be the work of a state-sponsored actor or hired contractor.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.