CPUID Breach Distributes STX RAT via Trojanized CPU-Z and HWMonitor Downloads
ID: b2923d41-d101-5796-8192-28ea1d3e032f
STIX ID: report--b2923d41-d101-5796-8192-28ea1d3e032f
Feed Name: The Hacker News
Threat actors briefly compromised cpuid.com (approx. April 9–10, 2026) to swap legitimate CPU-Z and HWMonitor download links with malicious sites serving trojanized installers and ZIPs that side-loaded a malicious CRYPTBASE.dll, which downloaded and executed STX RAT (HVNC/infostealer). Vendors observed over 150 victims (primarily individuals) across Brazil, Russia, and China, noted reuse of C2 domains and infection chains from a previous fake FileZilla campaign, and confirmed legitimate signed binaries themselves were not altered.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
