By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: CPUID Breach Distributes STX RAT via Trojanized CPU-Z and HWMonitor Downloads
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Computing > CPUID Breach Distributes STX RAT via Trojanized CPU-Z and HWMonitor Downloads
Computing

CPUID Breach Distributes STX RAT via Trojanized CPU-Z and HWMonitor Downloads

News Room
Last updated: 2026/04/12 at 2:05 AM
News Room Published 12 April 2026
Share
CPUID Breach Distributes STX RAT via Trojanized CPU-Z and HWMonitor Downloads
SHARE

Ravie LakshmananApr 12, 2026Malware / Threat Intelligence

Unknown threat actors compromised CPUID (“cpuid[.]com”), a website that hosts popular hardware monitoring tools like CPU-Z, HWMonitor, HWMonitor Pro, and PerfMonitor, for less than 24 hours to serve malicious executables for the software and deploy a remote access trojan called STX RAT.

The incident lasted from approximately April 9, 15:00 UTC, to about April 10, 10:00 UTC, with the download URLs for CPU-Z and HWMonitor installers replaced with links to malicious websites.

In a post shared on X, CPUID confirmed the breach, attributing it to a compromise of a “secondary feature (basically a side API)” that caused the main site to randomly display malicious links. It’s worth noting that the attack did not impact its signed original files.

According to Kaspersky, the names of the rogue websites are as follows –

  • cahayailmukreatif.web[.]id
  • pub-45c2577dbd174292a02137c18e7b1b5a.r2[.]dev
  • transitopalermo[.]com
  • vatrobran[.]hr

“The trojanized software was distributed both as ZIP archives and as standalone installers for the aforementioned products,” the Russian cybersecurity company said. “These files contain a legitimate signed executable for the corresponding product and a malicious DLL, which is named ‘CRYPTBASE.dll’ to leverage the DLL side-loading technique.”

The malicious DLL, for its part, contacts an external server and executes additional payloads, but not before performing anti-sandbox checks to sidestep detection. The end goal of the campaign is to deploy STX RAT, a RAT with HVNC and broad infostealer capabilities.

STX RAT “exposes a broad command set for remote control, follow-on payload execution, and post-exploitation actions (e.g., in-memory execution of EXE/DLL/PowerShell/shellcode, reverse proxy/tunneling, desktop interaction),” eSentire said in an analysis of the malware last week.

The command-and-control (C2) server address and the connection configuration have been reused from a prior campaign that leveraged trojanized FileZilla installers hosted on bogus sites to deploy the same RAT malware. The activity was documented by Malwarebytes early last month.

Kaspersky said it has identified more than 150 victims, mostly individuals who were affected by the incident. However, organizations in retail, manufacturing, consulting, telecommunications, and agriculture have also been impacted. Most of the infections are located in Brazil, Russia, and China.

“The gravest mistake attackers made was to reuse the same infection chain involving STX RAT, and the same domain names for C2 communication, from the previous attack related to fake FileZilla installers,” Kaspersky said. “The overall malware development/deployment and operational security capabilities of the threat actor behind this attack are quite low, which, in turn, made it possible to detect the watering hole compromise as soon as it started.”

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Bitdefender Antivirus Plus Review: Premium Protection That Goes Well Beyond Basics Bitdefender Antivirus Plus Review: Premium Protection That Goes Well Beyond Basics
Next Article The Pixel 11 series could be the first to use Samsung’s latest display tech The Pixel 11 series could be the first to use Samsung’s latest display tech
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

How a Fortune 500 Legal Team Saved 12,000 Hours Using ChatGPT Enterprise and Claude for Contract Analysis – Chat GPT AI Hub
How a Fortune 500 Legal Team Saved 12,000 Hours Using ChatGPT Enterprise and Claude for Contract Analysis – Chat GPT AI Hub
Computing
Copilot Takes a Backseat in Microsoft’s Latest Windows 11 Update
Copilot Takes a Backseat in Microsoft’s Latest Windows 11 Update
News
Today only: Grab AirPods Max USB-C for 9.95 (0 off)
Today only: Grab AirPods Max USB-C for $399.95 ($150 off)
News
Kuaishou’s text-to-video model Kling introduces new video generation feature, results go viral in China · TechNode
Kuaishou’s text-to-video model Kling introduces new video generation feature, results go viral in China · TechNode
Computing

You Might also Like

How a Fortune 500 Legal Team Saved 12,000 Hours Using ChatGPT Enterprise and Claude for Contract Analysis – Chat GPT AI Hub
Computing

How a Fortune 500 Legal Team Saved 12,000 Hours Using ChatGPT Enterprise and Claude for Contract Analysis – Chat GPT AI Hub

14 Min Read
Kuaishou’s text-to-video model Kling introduces new video generation feature, results go viral in China · TechNode
Computing

Kuaishou’s text-to-video model Kling introduces new video generation feature, results go viral in China · TechNode

4 Min Read
TSMC’s market value surpasses a trillion dollars for the first time · TechNode
Computing

TSMC’s market value surpasses a trillion dollars for the first time · TechNode

1 Min Read
Baidu shares surge on growth prospects of robotaxi business · TechNode
Computing

Baidu shares surge on growth prospects of robotaxi business · TechNode

2 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?