logo

CPUID site hijacked to serve malware instead of HWMonitor downloads

ID: e6b01f85-eeb6-5b67-82d9-14f0888a841a

STIX ID: report--e6b01f85-eeb6-5b67-82d9-14f0888a841a

Feed Name: The Register (Security)

Threat Score
70/100

Date Published: 2026-04-10

Date Updated: 2026-04-26

Author: Carly Page

...
...

CPUID's website was briefly manipulated via a compromised backend component between April 9–10, causing some legitimate download links (e.g., HWMonitor/CPU‑Z) to point to malicious installers; the malware used a fake CRYPTBASE.dll, communicated with command‑and‑control servers, ran largely in memory (via PowerShell), compiled and injected a .NET payload, and showed behavior consistent with credential theft and reuse of infrastructure seen in earlier campaigns. CPUID reports original signed builds were not altered and the issue has been fixed, but scope and initial access details remain unknown.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.