The CPUID Watering Hole Attack Turning CPU-Z into a Trojan
ID: 675a4a1d-e6a6-5b2b-a167-93e4e05b0f7d
STIX ID: report--675a4a1d-e6a6-5b2b-a167-93e4e05b0f7d
Feed Name: securityonline.info
On April 9–10, 2026, cpuid.com was briefly compromised in a watering-hole campaign that replaced legitimate CPU‑Z, HWMonitor and related installers with packages containing a malicious CRYPTBASE.dll; the DLL sideloading technique led to execution of a loader that deployed the known STX RAT to ~150+ victims (individuals and organizations across retail, manufacturing, consulting, telecommunications and agriculture) concentrated in Brazil, Russia and China. Kaspersky published telemetry, malicious domains and recommended actions (DNS log review, filesystem audits for CRYPTBASE.dll, and YARA scans for the STX RAT).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
