Threat reportMalwareTL-2026-0249

Infostealer.Speagle — Supply Chain Compromise via Cobra DocGuard Targeting Ballistic Missile Intelligence

criticalACTIVE

Infostealer.Speagle (TL-2026-0249), also tracked as Infostealer.Speagle, is a critical-severity malware campaign, first published 2026-03-19. It is attributed to Runningcrab (China) with low confidence, affects EsafeNet (NSFOCUS) Cobra DocGuard Client, maps to 22 MITRE ATT&CK techniques (T1005, T1007, T1012), and is covered by 9 detection rules and 22 indicators of compromise.

Severity
CRITICALAssessed severity
CVEs
0None referenced
Techniques
22MITRE ATT&CK
Actors
1Runningcrab
Detection rules
9SPL · KQL · Sigma
IOCs
22Indicators of compromise

Key facts for TL-2026-0249

Threat ID
TL-2026-0249
Also known as
Infostealer.Speagle, Speagle
Severity
CRITICAL
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution
Runningcrab
Attribution confidence
LOW
Nation-state nexus
China
Motivation
ESPIONAGE
Target sectors
defense, government, military, aerospace, technology, manufacturing
Target regions
East Asia, China, Asia-Pacific
Detection rules
9
Indicators of compromise
22

Malware and tooling in Infostealer.Speagle

Malware and tooling: Infostealer.Speagle, Custom HTTP over compromised Cobra DocGuard CDGServer3

How Infostealer.Speagle works

A novel .NET infostealer dubbed Speagle, attributed to threat actor Runningcrab, parasitically leverages Cobra DocGuard document security software for C2 communication, persistence, and self-deletion. One variant specifically hunts for documents related to Chinese ballistic missiles (Dongfeng-27), indicating state-level intelligence collection objectives. The malware uses AES-128 CBC encrypted exfiltration over HTTP via compromised Cobra DocGuard servers.

Infostealer.Speagle is a 32-bit .NET executable that represents a sophisticated parasitic threat targeting organizations running EsafeNet's Cobra DocGuard document security software. The malware was discovered by Broadcom/Symantec researchers and attributed to a previously undocumented threat actor tracked as Runningcrab.

Speagle operates in three distinct collection phases. In Phase 1 (System Identification), it constructs an ErrorReport structure containing the Windows username, computer hostname, and Cobra DocGuard client identifiers extracted from UniqueClientCode.ini (ClientIDID) and PackageInfo.ini (No= value). In Phase 2 (System Enumeration), it performs extensive WMI queries across three scopes: root\cimv2 (targeting 13 classes including Win32_Account, Win32_Process, Win32_Service, Win32_Share, Win32_Timezone), root\Microsoft\Windows\TaskScheduler (MSFT_ScheduledTask), and root\StandardCimv2 (network and firewall rules). It also enumerates directories to depth 2 (excluding Windows, Users, PerfLogs, System Volume Information, $Recycle.Bin) and user profile folders to depth 5 (Documents, Downloads, Desktop, AppData). In Phase 3 (Browser and Credential Theft), it searches AppData for browser databases containing History, Web Data, and Login Data files, executing SQLite queries to extract URLs, autofill data, downloads, omnibox shortcuts, and bookmarks.

A particularly notable variant (SHA256: dcd3f06093bf34d81837d837c5a5935beb859ba6258e5a80c3a5f95638a13d4d) includes functionality to search for documents related to Chinese ballistic missiles, specifically the Dongfeng-27 (CSS-X-24). Keywords include ballistic missile, cruise missile, Dongfeng, Changjian, supersonic, hypersonic, thermal protection, warhead, aerospace, antenna, nozzle, ceramic, and composite. This strongly indicates state-level intelligence collection objectives, likely by a nation-state adversary or private contractor operating on behalf of a government.

For C2 communication, Speagle masquerades its traffic as legitimate Cobra DocGuard client-server communication by sending HTTP POST requests to compromised Cobra DocGuard servers at the CDGServer3/CDGClientDiagnostics endpoint with flag=syn_user_policy parameter. The malware uses a distinctive User-Agent string 'Raw HTML Reader' and custom HTTP headers (X-Request-Name, X-Request-ID, X-Request-No, X-Request-Time). Data is serialized as XML, compressed via Deflate, encrypted with AES-128 CBC (PKCS#7 padding) using the first 16 bytes of SHA256('kAozqXwNES5yjGcZUlXeI4zigg68aZI4') as the key, and hexlified before transmission.

Speagle employs a two-stage self-deletion mechanism. It first attempts to leverage the Cobra DocGuard device driver by opening \\.\FileLock and sending a DeviceIoControl call with IoControlCode 0x85272220, passing its own process ID. If this fails, it falls back to a file-based technique: renaming its executable to 6 random uppercase letters and calling SetFileInformationByHandle with FileDispositionInfo to set the DeleteFile flag.

This threat represents the second known exploitation of Cobra DocGuard infrastructure, following the Carderbee APT campaign in 2023 that used the same software to deliver PlugX/Korplug backdoors to organizations in Hong Kong. While no direct link between Runningcrab and Carderbee has been established, the deliberate targeting of Cobra DocGuard infrastructure suggests the developer had detailed knowledge of prior supply chain vulnerabilities in EsafeNet products. Cobra DocGuard is produced by EsafeNet, a subsidiary of Chinese information security firm NSFOCUS.

MITRE ATT&CK techniques used in TL-2026-0249

collection

T1005 Data from Local System; T1119 Automated Collection; T1213 Data from Information Repositories

discovery

T1007 System Service Discovery; T1012 Query Registry; T1057 Process Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery; T1087 Account Discovery; T1135 Network Share Discovery; T1518 Software Discovery

defense-evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1070 Indicator Removal; T1140 Deobfuscate/Decode Files or Information

exfiltration

T1041 Exfiltration Over C2 Channel

execution

T1047 Windows Management Instrumentation

command-and-control

T1071 Application Layer Protocol; T1132 Data Encoding

initial-access

T1195 Supply Chain Compromise

persistence

T1547 Boot or Logon Autostart Execution

credential-access

T1555 Credentials from Password Stores

Affected products and versions in Infostealer.Speagle

  • EsafeNet (NSFOCUS) — Cobra DocGuard Client
    Vulnerable versions: All known versions
  • Microsoft — Windows
    Vulnerable versions: Windows 7+; Windows Server 2012+

Remediation for Infostealer.Speagle

Immediate actions

  • Block C2 IPs 60.30.147.18 and 222.222.254.165 at network perimeter
  • Hunt for HTTP traffic with User-Agent 'Raw HTML Reader' in proxy/firewall logs
  • Search for CDGServer3/CDGClientDiagnostics?flag=syn_user_policy in HTTP request logs
  • Scan endpoints for SHA256 hashes listed in IOCs
  • Check for anomalous DeviceIoControl calls to \\.\FileLock driver

Workarounds

  • Restrict outbound HTTP from Cobra DocGuard client systems to known-good CDG servers only
  • Disable or quarantine Cobra DocGuard installations until supply chain integrity verified
  • Block HTTP POST requests containing X-Request-Name and X-Request-ID custom headers from non-browser processes

Longer-term hardening

  • Implement application allowlisting to prevent unauthorized .NET executables
  • Deploy EDR with behavioral detection for WMI enumeration chains and browser credential access
  • Monitor Cobra DocGuard update channels for unauthorized modifications
  • Implement network segmentation between Cobra DocGuard servers and internet-facing infrastructure
  • Review Cobra DocGuard deployment necessity and consider alternatives

Weaknesses (CWE) in Infostealer.Speagle

CWE-506, CWE-319, CWE-522

Timeline of Infostealer.Speagle

  • ESET reports Cobra DocGuard supply chain compromise targeting Hong Kong gambling company — first known exploitation of CDG infrastructure
  • Symantec discloses Carderbee APT using Cobra DocGuard to deliver PlugX/Korplug backdoor to approximately 100 victims in Hong Kong
  • Broadcom/Symantec Threat Hunter Team identifies novel Infostealer.Speagle samples targeting Cobra DocGuard users
  • Variant with Dongfeng-27 ballistic missile keyword searching functionality identified (SHA256: dcd3f06093bf34d81837d837c5a5935beb859ba6258e5a80c3a5f95638a13d4d)
  • Threat actor tracked as Runningcrab — no association with known threat groups established; assessed as likely state-sponsored or private contractor
  • C2 infrastructure at 60.30.147.18:8091 and 222.222.254.165:8090 assessed as active — compromised Cobra DocGuard servers
  • Symantec/Broadcom publishes full technical analysis of Infostealer.Speagle and Runningcrab threat actor
  • As of 2026-05-29, Speagle/Runningcrab remains ACTIVE: no CVE (CISA KEV N/A), no vendor patch since the actor abuses compromised Cobra DocGuard servers as C2, and no reported takedown of the undisrupted, unattributed espionage actor. The only major May 2026 takedown was the unrelated Glassworm botnet, and no successor or remediation event has emerged since the 2026-03-19 Symantec disclosure.

Sources cited for Infostealer.Speagle

Detection coverage for TL-2026-0249

As of 2026-03-19, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0249 across Splunk SPL, Microsoft KQL and Sigma, covering 22 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
22 indicators of compromise · Red and above. Compare plans

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats