logo

Securing the Software Supply Chain: How SentinelOne’s AI EDR Autonomously Blocked the CPU-Z Watering Hole Cyber Attack

ID: 89d1190c-a5a6-5dc5-9c8f-04addc6d4842

STIX ID: report--89d1190c-a5a6-5dc5-9c8f-04addc6d4842

Feed Name: SentinelOne Blog

Threat Score
90/100

Date Published: 2026-04-14

Date Updated: 2026-04-30

Author: SentinelOne

...
...

On April 9, 2026, CPUID's download API was compromised to distribute a signed, trojanized CPU-Z installer delivering STX RAT via a reflective in-memory loader; the campaign affected 150+ confirmed victims (targeting IT/professional users), used persistence (registry Run key, scheduled task, MSBuild proj files), reused C2 infrastructure (supp0v3.com and 147.45.178.61) seen in prior campaigns, and was detected by behavioral EDR indicators (anomalous API resolution, RWX allocations, process injection) which enabled rapid containment.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.