惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Microsoft Azure Blog
Microsoft Azure Blog
GbyAI
GbyAI
P
Proofpoint News Feed
Engineering at Meta
Engineering at Meta
Recent Announcements
Recent Announcements
L
LangChain Blog
B
Blog
阮一峰的网络日志
阮一峰的网络日志
Microsoft Security Blog
Microsoft Security Blog
博客园 - 【当耐特】
M
MIT News - Artificial intelligence
D
Docker
WordPress大学
WordPress大学
J
Java Code Geeks
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
The GitHub Blog
The GitHub Blog
博客园 - 叶小钗
Last Week in AI
Last Week in AI
Stack Overflow Blog
Stack Overflow Blog
有赞技术团队
有赞技术团队
MyScale Blog
MyScale Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
MongoDB | Blog
MongoDB | Blog
博客园 - Franky

Help Net Security

Your work apps are quietly handing 19 data points to someone ChatGPT advanced account security adds passkeys and hardware keys Week in review: High-severity LPE vulnerability in the Linux kernel, cPanel 0-day exploited for months Automating Pentest Delivery: A Step-by-Step Guide - PlexTrac Open-source privacy proxy masks PII before prompts reach external AI services Shadow AI risks deepen as 31% of users get no employer training Identity is the control plane for distributed infrastructure AI traffic is getting bigger, louder, and less predictable New infosec products of the month: April 2026 cPanel zero-day exploited for months before patch release (CVE-2026-41940) Cisco releases open-source toolkit for verifying AI model lineage Met Police face criticism for using AI to spy on their own officers Nine-year-old Linux kernel flaw enables reliable local privilege escalation (CVE-2026-31431) Hacker with a special interest in breaching sports institutions ends behind bars - Help Net Security IP Fabric MCP server adds governance and control to enterprise AIOps workflows - Help Net Security Aqua Compass MCP server enables real-time investigation and containment of runtime threats - Help Net Security Google brings instant email verification to Android, no OTP needed - Help Net Security If cyber espionage via HDMI worries you, NCSC built a device to stop it - Help Net Security Apple fixes iPhone bug that let FBI retrieve deleted Signal messages(CVE-2026-28950) - Help Net Security GopherWhisper APT group hides command and control traffic in Slack and Discord - Help Net Security OpenAI tackles a bad habit people have when interacting with AI - Help Net Security A year in, Zoom's CISO reflects on balancing security and business - Help Net Security Scenario: Open-source framework for automated AI app red-teaming - Help Net Security GDPR works, but only where someone enforces it - Help Net Security Ransomware, fraud, and lawsuits drive cyber insurance claims to new peaks - Help Net Security Google’s Workspace Intelligence promises privacy while running on your data - Help Net Security Cyberattack on French government agency triggers phishing alert - Help Net Security Claude Mythos finds 271 Firefox flaws, Mozilla believes zero-days are numbered - Help Net Security Prove Identity Platform connects verification, authentication, and fraud prevention - Help Net Security New Mirai variants target routers and DVRs in parallel campaigns - Help Net Security
Hackers hijacked CPUID downloads, served STX RAT to victims
Zeljka Zorz · 2026-04-13 · via Help Net Security

If you tried to download software from CPUID’s website late last week, you might have downloaded malware instead.

“Investigations are still ongoing, but it appears that a secondary feature (basically a side API) was compromised for approximately six hours between April 9 and April 10, causing the main website to randomly display malicious links (our signed original files were not compromised),” Samuel Demeulemeester, a contributor to CPUID, stated on Friday, and apologized to affected users.

“The breach was found and has since been fixed,” he added.

A poisoned “watering hole”

CPUID (at cpuid[.]com) is a website that hosts free software utilities, primarily for Windows and Android.

Among its most popular utilities are HWMonitor, a hardware monitoring program that reads a PC’s main health sensors, and CPU-Z, a utility that collects detailed information about PCs’ processor, codename, process, package, and cache levels.

Alerts that something was wrong started popping up on Reddit on Friday, April 10, and one user noted that their antivirus flagged the downloaded HWiNFO_Monitor_Setup.exe as malicious.

Kaspersky researchers say that the CPUID website redirected to malicious download from April 9, 15:00 UTC to April 10, 10:00 UTC.

“The trojanized software was distributed both as ZIP archives and as standalone installers for aforementioned products. These files contain a legitimate signed executable for the corresponding product and a malicious DLL which is named CRYPTBASE.dll to leverage the DLL Sideloading technique,” they explained.

“The malicious DLL is responsible for C2 connection and further payload execution. Prior to this, it also performs a set of anti-sandbox checks and, if all the checks have passed, it connects to the C2 server.”

Malware researcher Giuseppe Massaro also flagged the CPU-Z, HWMonitor Pro, PerfMonitor, and PowerMAX downloads as trojanized/malicious.

“CPUID’s original signed binaries were NOT compromised — the attacker served their own trojanized packages via redirect,” Massaro found. “The compromised API caused download links to randomly redirect to malicious URLs (Cloudflare R2 buckets).”

The command and control domain (at supp0v3[.]com) from which the malware has been downloaded has been previously used in a malware campaign targeting FileZilla users with a lookalike domain and a trojanized download.

A subdomain (ai.supp0v3.com) esposed the backend server, Massaro also discovered during his analysis.

“The server uses a stolen or self-signed VK.com (VKontakte) wildcard certificate with Russian locality data (Saint Petersburg). This, combined with the bulletproof hosting choice (Global Connectivity Solutions — a provider frequently used for malicious hosting), strongly suggests a Russian-nexus threat actor,” he noted.

“The same IP was used for earlier .url shortcut exploits (CVE-2023-36025 SmartScreen bypass) targeting LibreOffice and Google Drive downloads, sharing VBS payloads via WebDAV (file://147.45.178.61@80/file/…). This connects the current DLL sideloading campaign to an earlier Windows shortcut exploit campaign by the same actor.”

What to do?

The malicious payload in this watering hole campaign is the STX RAT, a persistent remote access trojan with credential and data theft capabilities. According to eSentire, it’s after browser credentials/cookies, crypto-wallets, and FTP client credentials.

Kaspersky researchers pointed out that the attackers’ mistakes – reusing a previously flagged infection chain and domain names used in previous attacks – resulted in a speedy detection of this latest watering hole attack.

Nevertheless, based on their telemerty, they have identified more than 150 victims, most of them individuals.

“However, several organizations from various sectors, including retail, manufacturing, consulting, telecommunications and agriculture, were also affected with most infections in Brazil, Russia and China,” they added.

They advised organizations to check their systems for traces of the malicious archives and executable files related to this attack, and to examine DNS logs for the malicious websites from which the trojanized installers have been downloaded.

If evidence of compromise is discovered, organizations (and individuals) should clean affected systems and change all the credentials the malware might have compromised.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!