Cybersecurity — 2026-04-11
CPUID Website Compromised, CPU-Z and HWMonitor Downloads Served Malware for Six Hours
Attackers compromised CPUID's API infrastructure and redirected download links for CPU-Z and HWMonitor to trojanized binaries containing the STX RAT remote access trojan. The compromise lasted approximately six hours on April 9-10. The malware used DLL sideloading via a fake CRYPTBASE.dll, executed entirely in memory across five stages using reflective PE loading and XOR decryption, leaving no disk artifacts. CPUID confirmed the breach has been fixed but original signed files were never compromised.
3 sources
- CPUID hacked to deliver malware via CPU-Z, HWMonitor downloads - BleepingComputer
- CPUID hijacked to serve malware as HWMonitor downloads - The Register
- Monitoring the Monitor: How CPUID's HWMonitor Supply Chain Was Hijacked to Deploy STX RAT - Cyderes
View in full brief →