• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
cpuid breach distributes stx rat via trojanized cpu z and hwmonitor

CPUID Breach Distributes STX RAT via Trojanized CPU-Z and HWMonitor Downloads

You are here: Home / General Cyber Security News / CPUID Breach Distributes STX RAT via Trojanized CPU-Z and HWMonitor Downloads
April 12, 2026

Unknown threat actors compromised CPUID (“cpuid[.]com”), a website that hosts popular hardware monitoring tools like CPU-Z, HWMonitor, HWMonitor Pro, and PerfMonitor, for less than 24 hours to serve malicious executables for the software and deploy a remote access trojan called STX RAT.

The incident lasted from approximately April 9, 15:00 UTC, to about April 10, 10:00 UTC, with the download URLs for CPU-Z and HWMonitor installers replaced with links to malicious websites.

In a post shared on X, CPUID confirmed the breach, attributing it to a compromise of a “secondary feature (basically a side API)” that caused the main site to randomly display malicious links. It’s worth noting that the attack did not impact its signed original files.

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


Cybersecurity

According to Kaspersky, the names of the rogue websites are as follows –

  • cahayailmukreatif.web[.]id
  • pub-45c2577dbd174292a02137c18e7b1b5a.r2[.]dev
  • transitopalermo[.]com
  • vatrobran[.]hr

“The trojanized software was distributed both as ZIP archives and as standalone installers for the aforementioned products,” the Russian cybersecurity company said. “These files contain a legitimate signed executable for the corresponding product and a malicious DLL, which is named ‘CRYPTBASE.dll’ to leverage the DLL side-loading technique.”

The malicious DLL, for its part, contacts an external server and executes additional payloads, but not before performing anti-sandbox checks to sidestep detection. The end goal of the campaign is to deploy STX RAT, a RAT with HVNC and broad infostealer capabilities.

STX RAT “exposes a broad command set for remote control, follow-on payload execution, and post-exploitation actions (e.g., in-memory execution of EXE/DLL/PowerShell/shellcode, reverse proxy/tunneling, desktop interaction),” eSentire said in an analysis of the malware last week.

Cybersecurity

The command-and-control (C2) server address and the connection configuration have been reused from a prior campaign that leveraged trojanized FileZilla installers hosted on bogus sites to deploy the same RAT malware. The activity was documented by Malwarebytes early last month.

Kaspersky said it has identified more than 150 victims, mostly individuals who were affected by the incident. However, organizations in retail, manufacturing, consulting, telecommunications, and agriculture have also been impacted. Most of the infections are located in Brazil, Russia, and China.

“The gravest mistake attackers made was to reuse the same infection chain involving STX RAT, and the same domain names for C2 communication, from the previous attack related to fake FileZilla installers,” Kaspersky said. “The overall malware development/deployment and operational security capabilities of the threat actor behind this attack are quite low, which, in turn, made it possible to detect the watering hole compromise as soon as it started.”

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.


Some parts of this article are sourced from:
thehackernews.com

Previous Post: «adobe patches actively exploited acrobat reader flaw cve 2026 34621 Adobe Patches Actively Exploited Acrobat Reader Flaw CVE-2026-34621

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • CPUID Breach Distributes STX RAT via Trojanized CPU-Z and HWMonitor Downloads
  • Adobe Patches Actively Exploited Acrobat Reader Flaw CVE-2026-34621
  • Citizen Lab: Law Enforcement Used Webloc to Track 500 Million Devices via Ad Data
  • GlassWorm Campaign Uses Zig Dropper to Infect Multiple Developer IDEs
  • Browser Extensions Are the New AI Consumption Channel That No One Is Talking About
  • Google Rolls Out DBSC in Chrome 146 to Block Session Theft on Windows
  • Marimo RCE Flaw CVE-2026-39987 Exploited Within 10 Hours of Disclosure
  • Backdoored Smart Slider 3 Pro Update Distributed via Compromised Nextend Servers
  • EngageLab SDK Flaw Exposed 50M Android Users, Including 30M Crypto Wallets
  • UAT-10362 Targets Taiwanese NGOs with LucidRook Malware in Spear-Phishing Campaigns

Copyright © TheCyberSecurity.News, All Rights Reserved.