CPUID watering hole attack spreads STX RAT malware
ID: 9a6c3538-525a-5f01-b530-c63f019c9809
STIX ID: report--9a6c3538-525a-5f01-b530-c63f019c9809
Feed Name: Security Affairs
Threat Score
CPUID's website was briefly compromised to serve trojanized CPU‑Z and HWMonitor installers that used DLL sideloading (malicious CRYPTBASE.dll) to deliver the STX RAT. Kaspersky reported the April 9–10, 2026 campaign, linked reused C2/configuration from a previous fake FileZilla operation, and published indicators after identifying about 150 victims in multiple countries.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
