logo

Hackers hijacked CPUID downloads, served STX RAT to victims

ID: d0f98f80-3436-542b-ae14-36d8de88ecbe

STIX ID: report--d0f98f80-3436-542b-ae14-36d8de88ecbe

Feed Name: Help Net Security

Threat Score
72/100

Date Published: 2026-04-13

Date Updated: 2026-04-28

Author: Zeljka Zorz

...
...

CPUID's website was briefly compromised (April 9–10), causing legitimate download links for utilities like CPU-Z and HWMonitor to redirect to trojanized packages hosted on malicious Cloudflare R2 buckets; those installers contained a malicious CRYPTBASE.dll that used DLL sideloading, anti-sandbox checks, and C2 communication to deploy the STX RAT, which steals browser credentials, crypto-wallets, and FTP credentials — researchers identified ~150 victims (individuals and organizations) and advised checking downloads, DNS logs, and cleaning/credential resets if compromised.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.