logo

Hackers Abuse Legitimate HWMonitor Binary to Load Malicious DLL Payload

ID: 57a6709b-dd07-5a92-b262-c2ba97d48154

STIX ID: report--57a6709b-dd07-5a92-b262-c2ba97d48154

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-05-14

Date Updated: 2026-05-22

Author: Tushar Subhra Dutta

...
...

Attackers distributed a trojanized HWMonitor installer that includes a malicious CRYPTBASE.dll which sideloads into the legitimate HWMonitor_x64.exe to execute a multi-stage, reflective in-memory loader delivering STX RAT. The RAT enables remote access, screenshot capture, system and security-product enumeration, and persistence; the report includes IoCs (distribution URL, C2 endpoint, filenames, and hashes) and defensive recommendations such as monitoring DLL loads, blocking unexpected DLLs, and enabling memory-based detections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.