CPUID Site Hacked to Push STX RAT via Fake CPU-Z, HWMonitor

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- CPUID confirmed attackers compromised cpuid[.]com from ~April 9, 15:00 UTC to ~April 10, 10:00 UTC — under 24 hours — by exploiting a "secondary feature (basically a side API)" to randomly display malicious download links for CPU-Z, HWMonitor, HWMonitor Pro, and PerfMonitor.
- STX RAT was the end payload, a remote access trojan with HVNC and broad infostealer capabilities that Kaspersky said was delivered via trojanized ZIP archives and standalone installers pairing legitimate signed executables with a malicious 'CRYPTBASE.dll' using DLL side-loading.
- Kaspersky identified more than 150 victims — mostly individuals, plus organizations in retail, manufacturing, consulting, telecommunications, and agriculture — with infections concentrated in Brazil, Russia, and China.
- Breakglass Intelligence tied the breach to a 10-month campaign dating to July 2025 (earliest sample "superbad.exe" hitting C2 95.216.51[.]236) and assessed the operator is a Russian-speaking threat actor, either financially motivated or working as an initial access broker.
- Kaspersky flagged the attackers' sloppy tradecraft: the C2 address and connection configuration were reused from a prior trojanized-FileZilla-installer campaign documented by Malwarebytes, which Kaspersky called "the gravest mistake" that enabled early detection of the watering-hole compromise.
Why it matters: CPUID tools are downloaded by millions for routine hardware diagnostics, so a single compromised page turned trusted software into a remote-access trojan with credential-stealing and HVNC capabilities. The 10-month, 150+ victim footprint shows deliberate infrastructure-building — and the attackers' own C2 reuse from a prior FileZilla campaign is what exposed them, per Kaspersky.
Ask SkimNews



