logo

The CPUID Watering Hole Attack Turning CPU-Z into a Trojan

ID: 675a4a1d-e6a6-5b2b-a167-93e4e05b0f7d

STIX ID: report--675a4a1d-e6a6-5b2b-a167-93e4e05b0f7d

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-04-13

Date Updated: 2026-04-23

Author: Ddos

...
...

On April 9–10, 2026, cpuid.com was briefly compromised in a watering-hole campaign that replaced legitimate CPU‑Z, HWMonitor and related installers with packages containing a malicious CRYPTBASE.dll; the DLL sideloading technique led to execution of a loader that deployed the known STX RAT to ~150+ victims (individuals and organizations across retail, manufacturing, consulting, telecommunications and agriculture) concentrated in Brazil, Russia and China. Kaspersky published telemetry, malicious domains and recommended actions (DNS log review, filesystem audits for CRYPTBASE.dll, and YARA scans for the STX RAT).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.