logo

CPUID Breach Distributes STX RAT via Trojanized CPU-Z and HWMonitor Downloads

ID: b2923d41-d101-5796-8192-28ea1d3e032f

STIX ID: report--b2923d41-d101-5796-8192-28ea1d3e032f

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2026-04-12

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Threat actors briefly compromised cpuid.com (approx. April 9–10, 2026) to swap legitimate CPU-Z and HWMonitor download links with malicious sites serving trojanized installers and ZIPs that side-loaded a malicious CRYPTBASE.dll, which downloaded and executed STX RAT (HVNC/infostealer). Vendors observed over 150 victims (primarily individuals) across Brazil, Russia, and China, noted reuse of C2 domains and infection chains from a previous fake FileZilla campaign, and confirmed legitimate signed binaries themselves were not altered.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.