By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: Speagle Malware Hijacks Cobra DocGuard to Steal Data via Compromised Servers
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Computing > Speagle Malware Hijacks Cobra DocGuard to Steal Data via Compromised Servers
Computing

Speagle Malware Hijacks Cobra DocGuard to Steal Data via Compromised Servers

News Room
Last updated: 2026/03/19 at 5:27 PM
News Room Published 19 March 2026
Share
Speagle Malware Hijacks Cobra DocGuard to Steal Data via Compromised Servers
SHARE

Ravie LakshmananMar 19, 2026Cyber Espionage / Threat Intelligence

Cybersecurity researchers have flagged a new malware dubbed Speagle that hijacks the functionality and infrastructure of a legitimate program called Cobra DocGuard.

“Speagle is designed to surreptitiously harvest sensitive information from infected computers and transmit it to a Cobra DocGuard server that has been compromised by the attackers, masking the data exfiltration process as legitimate communications between client and server,” Symantec and Carbon Black researchers said in a report published today.

Cobra DocGuard is a document security and encryption platform developed by EsafeNet. The abuse of this software in real-world attacks has been publicly recorded twice to date. In January 2023, ESET documented an intrusion where a gambling company in Hong Kong was compromised in September 2022 via a malicious update pushed by the software.

that August, Symantec highlighted the activity of a new threat cluster codenamed Carderbee, which was found using a trojanized version of the program to deploy PlugX, a backdoor widely used by Chinese hacking groups like Mustang Panda. The attacks targeted multiple organizations in Hong Kong and other Asian countries.

Speagle remains unattributed to date. But what makes the malware noteworthy is that it’s designed to gather and exfiltrate data from only those systems that have the Cobra DocGuard data protection software installed. The activity is being tracked under the moniker Runningcrab.

“This indicates deliberate targeting, possibly to facilitate intelligence collection or industrial espionage,” the Broadcom-owned threat hunting teams said. “At present, we believe the most likely hypotheses are that it is either the work of a state-sponsored actor or the work of a private contractor available for hire.”

Exactly how the malware is delivered to victims is unknown, although it’s suspected that it may have been done via a supply chain attack, as evidenced by the two aforementioned cases. 

In addition, the central role played by the security software and its infrastructure deserves a mention. Not only does Speagle use a legitimate Cobra DocGuard server for command-and-control (C2) and as a data exfiltration point, it also invokes a driver associated with the program to delete itself from the compromised host.

The 32-bit .NET executable, once launched, first checks the installation folder of Cobra DocGuard and then proceeds to harvest and transmit data from the infected machine in phases. This includes details about the system and files located in specific folders, such as those that contain web browser history and autofill data.

What’s more, one variant of Speagle has been found to incorporate additional functionality to turn on/off certain types of data collection, as well as search for files related to Chinese ballistic missiles like Dongfeng-27 (aka DF-27).

“Speagle is a novel, parasitic threat that cleverly makes use of Cobra DocGuard’s client to mask its malicious activity and its infrastructure to hide exfiltration traffic,” researchers said. “Its developer no doubt took notice of previous supply chain attacks using the software and may have selected it both for its perceived vulnerability and its high rate of use among targeted organizations.”

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article 3 Reasons Why This alt= 3 Reasons Why This $0.04 New Crypto Could Outperform Pepecoin (PEPE) in 2026
Next Article Google: AI tool helped prevent heat-trapping contrails Google: AI tool helped prevent heat-trapping contrails
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

Best MacBook deal: Save 0 on 15-inch 2025 MacBook Air M4
Best MacBook deal: Save $200 on 15-inch 2025 MacBook Air M4
News
Cisa tells US organisations to harden endpoint management after Stryker attack | Computer Weekly
Cisa tells US organisations to harden endpoint management after Stryker attack | Computer Weekly
News
Now Live: MetaWinners Community Launches $METAWIN Token Presale | HackerNoon
Now Live: MetaWinners Community Launches $METAWIN Token Presale | HackerNoon
Computing
Nintendo Switch 2 Update Just Gave Your Game Collection A Boost – Here’s How – BGR
Nintendo Switch 2 Update Just Gave Your Game Collection A Boost – Here’s How – BGR
News

You Might also Like

Now Live: MetaWinners Community Launches $METAWIN Token Presale | HackerNoon
Computing

Now Live: MetaWinners Community Launches $METAWIN Token Presale | HackerNoon

6 Min Read
Gen Z Consumer Behavior & How It Impacts Your Campaigns
Computing

Gen Z Consumer Behavior & How It Impacts Your Campaigns

2 Min Read
The Fragile Memory of Neural Networks, and the Metrics We Trust | HackerNoon
Computing

The Fragile Memory of Neural Networks, and the Metrics We Trust | HackerNoon

15 Min Read
Sidewalk scooter riders, beware: AI-powered ‘Lime Vision’ will soon call you out
Computing

Sidewalk scooter riders, beware: AI-powered ‘Lime Vision’ will soon call you out

4 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?