Speagle malware hijacks Cobra DocGuard to hide data exfiltration

by

A technical analysis by Symantec and Carbon Black reported today a new malware named Speagle that hijacks the functionality and infrastructure of the Cobra DocGuard document protection platform and exfiltrates data from infected machines.

KEY FACTS

  • Incident Speagle abuses Cobra DocGuard to mask malicious traffic
  • Malware 32-bit .NET infostealer that harvests system and browser data
  • Targets Only systems with Cobra DocGuard installed
  • Delivery Suspected supply chain attack with exact vector unknown

Speagle uses a legitimate Cobra DocGuard server for command and control and as a data exfiltration endpoint. The malware also invokes a driver associated with the security software to remove its components from the compromised host.

The 32-bit .NET executable first checks the Cobra DocGuard installation folder and then proceeds in phases to harvest and transmit data. Collected items include system details and files from folders that commonly hold web browser history and autofill data.

One variant includes controls to enable or disable certain data collection and searches for files related to Chinese ballistic missiles such as Dongfeng-27. The activity is tracked under the name Runningcrab and remains unattributed.

Supply chain compromise is suspected based on two prior recorded incidents that relied on trojanized updates in previous Carderbee attacks. Exact initial access for Speagle has not been confirmed.

WHY IT MATTERS

By abusing trusted security software and its infrastructure, the malware makes detection and response more difficult and raises the risk for organizations that use Cobra DocGuard.