CyberHappenings logo

Track cybersecurity events as they unfold. Sourced timelines. Filter, sort, and browse. Fast, privacy‑respecting. No invasive ads, no tracking.

Speagle malware leverages compromised Cobra DocGuard servers and infrastructure to exfiltrate sensitive data

First reported
Last updated
1 unique sources, 1 articles

Summary

Hide ▲

A newly identified malware family, Speagle, has been observed hijacking the legitimate Cobra DocGuard document security platform to surreptitiously collect and exfiltrate sensitive data from infected systems. The malware abuses Cobra DocGuard’s client-server architecture and compromised servers to blend malicious communications with legitimate traffic, ensuring stealth during exfiltration. Speagle specifically targets systems where Cobra DocGuard is installed, indicating deliberate selection of victims, likely for intelligence collection or industrial espionage purposes. The operational infrastructure overlaps with prior documented abuses of Cobra DocGuard in 2022–2023, suggesting a pattern of exploiting trusted software in supply chain attacks.

Timeline

  1. 19.03.2026 21:16 1 articles · 4h ago

    Speagle malware campaign leverages compromised Cobra DocGuard servers for data exfiltration

    A newly identified malware family, Speagle, has been observed hijacking the Cobra DocGuard document security platform to exfiltrate sensitive data from infected systems. The malware abuses Cobra DocGuard’s client-server architecture and compromised servers to blend malicious communications with legitimate traffic. Speagle specifically targets systems with Cobra DocGuard installed, indicating deliberate victim selection and potentially aligning with intelligence collection or industrial espionage. Operational activity is tracked under Runningcrab, with attribution currently unattributed. Initial evidence suggests a supply chain attack as the likely delivery vector.

    Show sources

Information Snippets