# Infostealer.Speagle — Supply Chain Compromise via Cobra DocGuard Targeting Ballistic Missile Intelligence

> A novel .NET infostealer dubbed Speagle, attributed to threat actor Runningcrab, parasitically leverages Cobra DocGuard document security software for C2 communication, persistence, and self-deletion. One variant specifically hunts for documents related to Chinese ballistic missiles (Dongfeng-27), indicating state-level intelligence collection objectives. The malware uses AES-128 CBC encrypted exfiltration over HTTP via compromised Cobra DocGuard servers.

- **Published:** 2026-03-19T12:00:00Z
- **Last reviewed:** 2026-03-19T12:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0249
- **ID:** TL-2026-0249
- **Severity:** CRITICAL
- **Category:** MALWARE
- **Status:** ACTIVE
- **Actor:** Runningcrab (China)
- **Detections:** 9 · **IOCs:** 22 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Infostealer.Speagle is a 32-bit .NET executable that represents a sophisticated parasitic threat targeting organizations running EsafeNet's Cobra DocGuard document security software. The malware was discovered by Broadcom/Symantec researchers and attributed to a previously undocumented threat actor tracked as Runningcrab.

Speagle operates in three distinct collection phases. In Phase 1 (System Identification), it constructs an ErrorReport structure containing the Windows username, computer hostname, and Cobra DocGuard client identifiers extracted from UniqueClientCode.ini (ClientIDID) and PackageInfo.ini (No= value). In Phase 2 (System Enumeration), it performs extensive WMI queries across three scopes: root\cimv2 (targeting 13 classes including Win32_Account, Win32_Process, Win32_Service, Win32_Share, Win32_Timezone), root\Microsoft\Windows\TaskScheduler (MSFT_ScheduledTask), and root\StandardCimv2 (network and firewall rules). It also enumerates directories to depth 2 (excluding Windows, Users, PerfLogs, System Volume Information, $Recycle.Bin) and user profile folders to depth 5 (Documents, Downloads, Desktop, AppData). In Phase 3 (Browser and Credential Theft), it searches AppData for browser databases containing History, Web Data, and Login Data files, executing SQLite queries to extract URLs, autofill data, downloads, omnibox shortcuts, and bookmarks.

A particularly notable variant (SHA256: dcd3f06093bf34d81837d837c5a5935beb859ba6258e5a80c3a5f95638a13d4d) includes functionality to search for documents related to Chinese ballistic missiles, specifically the Dongfeng-27 (CSS-X-24). Keywords include ballistic missile, cruise missile, Dongfeng, Changjian, supersonic, hypersonic, thermal protection, warhead, aerospace, antenna, nozzle, ceramic, and composite. This strongly indicates state-level intelligence collection objectives, likely by a nation-state adversary or private contractor operating on behalf of a government.

For C2 communication, Speagle masquerades its traffic as legitimate Cobra DocGuard client-server communication by sending HTTP POST requests to compromised Cobra DocGuard servers at the CDGServer3/CDGClientDiagnostics endpoint with flag=syn_user_policy parameter. The malware uses a distinctive User-Agent string 'Raw HTML Reader' and custom HTTP headers (X-Request-Name, X-Request-ID, X-Request-No, X-Request-Time). Data is serialized as XML, compressed via Deflate, encrypted with AES-128 CBC (PKCS#7 padding) using the first 16 bytes of SHA256('kAozqXwNES5yjGcZUlXeI4zigg68aZI4') as the key, and hexlified before transmission.

Speagle employs a two-stage self-deletion mechanism. It first attempts to leverage the Cobra DocGuard device driver by opening \\.\FileLock and sending a DeviceIoControl call with IoControlCode 0x85272220, passing its own process ID. If this fails, it falls back to a file-based technique: renaming its executable to 6 random uppercase letters and calling SetFileInformationByHandle with FileDispositionInfo to set the DeleteFile flag.

This threat represents the second known exploitation of Cobra DocGuard infrastructure, following the Carderbee APT campaign in 2023 that used the same software to deliver PlugX/Korplug backdoors to organizations in Hong Kong. While no direct link between Runningcrab and Carderbee has been established, the deliberate targeting of Cobra DocGuard infrastructure suggests the developer had detailed knowledge of prior supply chain vulnerabilities in EsafeNet products. Cobra DocGuard is produced by EsafeNet, a subsidiary of Chinese information security firm NSFOCUS.

## MITRE ATT&CK

- T1195 Supply Chain Compromise
- T1047 Windows Management Instrumentation
- T1547 Boot or Logon Autostart Execution
- T1036 Masquerading
- T1070 Indicator Removal
- T1027 Obfuscated Files or Information
- T1140 Deobfuscate/Decode Files or Information
- T1555 Credentials from Password Stores
- T1082 System Information Discovery
- T1083 File and Directory Discovery
- T1012 Query Registry
- T1007 System Service Discovery
- T1518 Software Discovery
- T1057 Process Discovery
- T1087 Account Discovery
- T1135 Network Share Discovery
- T1005 Data from Local System
- T1119 Automated Collection
- T1213 Data from Information Repositories
- T1071 Application Layer Protocol
- T1132 Data Encoding
- T1041 Exfiltration Over C2 Channel

## Sources

- [Symantec: New Malware Targets Users of Cobra DocGuard Software](https://www.security.com/threat-intelligence/speagle-cobradocguard-infostealer)
- [Carderbee APT: Legit Software in Supply Chain Attack Targeting Hong Kong](https://www.security.com/threat-intelligence/carderbee-software-supply-chain-certificate-abuse)
- [Chinese APT Targets Hong Kong in Supply Chain Attack (Dark Reading)](https://www.darkreading.com/cyberattacks-data-breaches/chinese-apt-targets-hong-kong-in-supply-chain-attack)
- [Carderbee Attacks: Hong Kong Organizations Targeted via Malicious Software Updates](https://thehackernews.com/2023/08/carderbee-attacks-hong-kong.html)
- [Inside China's Hosting Ecosystem: 18,000+ Malware C2 Servers Mapped](https://hunt.io/blog/china-hosting-malware-c2-infrastructure)
- [Broadcom/Symantec Threat Hunter Team — China-Linked Espionage Actors Whitepaper](https://sed-cms.broadcom.com/system/files/threat-hunter-whitepaper/2025-04/2025_04_ChinaLinked_Espionage_Actors.pdf)
- [Carderbee Hackers Abuse Microsoft Signing Keys in Supply Chain Attacks](https://petri.com/carderbee-hackers-supply-chain-attacks/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0249
