
Security experts have discovered a new piece of malware called Speagle which repurposes the functions and setup of a legitimate application known as Cobra DocGuard.
“Speagle’s purpose is to secretly obtain sensitive information from compromised computers and send it to a Cobra DocGuard server that attackers have taken over. This makes the process of stealing data appear as normal communication between the client and server,” researchers from Symantec and Carbon Black stated in their recent report.
EsafeNet’s Cobra DocGuard is a platform for securing and encrypting documents. There have been two publicly documented instances where this software was exploited in actual attacks. In January 2023, ESET reported an incident from September 2022 in which a Hong Kong-based gambling firm was infiltrated through a malicious update delivered via the software.
Later, in August, Symantec drew attention to the activities of a new threat group named Carderbee. This group was found to be using a compromised version of the program to deploy PlugX, a backdoor frequently used by Chinese hacking groups such as Mustang Panda. The attacks were aimed at various organizations in Hong Kong and other Asian countries.
As of now, the origin of Speagle is unknown. However, its unique feature is that it’s designed to collect and steal data only from systems that have Cobra DocGuard data protection software installed. This activity is being monitored under the name Runningcrab.
“This indicates a specific targeting strategy, potentially to aid in gathering intelligence or conducting industrial espionage,” stated the threat hunting teams owned by Broadcom. “Currently, we believe it’s most likely either the work of a government-backed entity or a private contractor available for hire.”
The method used to deliver the malware to victims is currently unknown, although a supply chain attack is suspected, based on the two cases mentioned earlier.
Furthermore, the vital role played by the security software and its infrastructure is noteworthy. Speagle not only uses a legitimate Cobra DocGuard server for command and control (C2) and as a point for stealing data, but it also uses a driver associated with the program to remove itself from the compromised device.
Once launched, the 32-bit .NET executable first checks the Cobra DocGuard installation folder. Then, it starts collecting and sending data from the infected machine step by step. This includes details about the system and files located in specific folders, such as those containing web browser history and autofill data.
Additionally, one version of Speagle includes extra functions to enable/disable specific types of data collection and to search for files related to Chinese ballistic missiles such as the Dongfeng-27 (DF-27).
“Speagle is a new and unusual threat that cleverly leverages Cobra DocGuard’s client to disguise its malicious activity and its infrastructure to conceal the theft of data,” the researchers concluded. “Its creator likely observed previous supply chain attacks that exploited the software and may have chosen it because of both its perceived weakness and its widespread use among targeted organizations.”
#cobra #compromised #data #docguard #info #malware #news #occurs #over #servers #speagle #steal #takes #theft #through — News
© Bulletproof Servers. All rights reserved.