Malware · 153 days ago
CPUID’s official website was compromised to serve trojanized installers for CPU-Z, HWMonitor, HWMonitor Pro, and PerfMonitor that included a malicious DLL. The attackers did not alter the signed executables but added a malicious cryptbase.dll loaded via DLL sideloading, bypassing signature verification and infecting users worldwide. This breaks the assumption that verifying digital signatures alone ensures installer integrity.
The compromise lasted about six hours from April 9 to 10, during which the website randomly redirected users to malicious download links. Kaspersky identified over 150 victims across sectors including manufacturing, retail, telecommunications, and education, with infections concentrated in Brazil, China, and Russia. The malware deployed was the STX RAT, capable of stealing browser credentials, cryptocurrency wallets, and FTP passwords.
This incident shows that supply chain attacks can evade signature-based defenses by injecting malicious DLLs alongside legitimate signed binaries. The risk persists because users and organizations relying solely on signature checks may still execute compromised installers that load malicious code at runtime. Supply chain trust assumptions must be reevaluated to address DLL sideloading threats.
6 sources covering this story
CPUID breach delivered malware via signed downloads.
Hackers hijacked CPUID downloads, served STX RAT to victims - Help Net Security
If you tried to download software from CPUID's website late last week, you might have downloaded malware instead.
CPUID Hacked to Serve Trojanized CPU-Z and HWMonitor Downloads
Download links were replaced by a Russian-speaking threat actor to distribute a recently emerged malware named STX RAT.
CPUID Breach Distributes STX RAT via Trojanized CPU-Z and HWMonitor Downloads
CPUID breach served STX RAT via trojanized CPU-Z downloads on April 9–10, impacting 150+ victims and multiple industries.
CPUID hijacked to serve malware as HWMonitor downloads
: Six-hour breach turned trusted links into a coin toss between legit tools and credential stealers
CPUID hacked to deliver malware via CPU-Z, HWMonitor downloads
Hackers gained access to an API for the CPUID project and changed the download links on the official website to serve malicious executables for the popular CPU-Z and HWMonitor tools.
Part of the PlainSec briefing for 2026-04-13