Securing the Software Supply Chain: How SentinelOne’s AI EDR Autonomously Blocked the CPU-Z Watering Hole Cyber Attack
ID: 89d1190c-a5a6-5dc5-9c8f-04addc6d4842
STIX ID: report--89d1190c-a5a6-5dc5-9c8f-04addc6d4842
Feed Name: SentinelOne Blog
On April 9, 2026, CPUID's download API was compromised to distribute a signed, trojanized CPU-Z installer delivering STX RAT via a reflective in-memory loader; the campaign affected 150+ confirmed victims (targeting IT/professional users), used persistence (registry Run key, scheduled task, MSBuild proj files), reused C2 infrastructure (supp0v3.com and 147.45.178.61) seen in prior campaigns, and was detected by behavioral EDR indicators (anomalous API resolution, RWX allocations, process injection) which enabled rapid containment.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
