CPUID Breach Distributes STX RAT via Trojanized CPU-Z and HWMonitor Downloads

CPUID (“cpuid[.]com”), a website that contains well-known hardware monitoring applications like CPU-Z, HWMonitor, HWMonitor Pro, and PerfMonitor, was penetrated by unknown threat actors for less than a day in order to serve malicious executables for the software and install a remote access trojan known as STX RAT.

The download URLs for the CPU-Z and HWMonitor installers were substituted with links to malicious websites during the period between around April 9, 15:00 UTC, and April 10, 10:00 UTC.

CPUID confirmed the breach in a post on X, blaming it on a “secondary feature (basically a side API)” intrusion that led to the main site displaying malicious URLs at random. It’s important to note that its signed original files were unaffected by the attack.

According to Kaspersky, the names of the rogue websites are as follows –

  • cahayailmukreatif.web[.]id
  • pub-45c2577dbd174292a02137c18e7b1b5a.r2[.]dev
  • transitopalermo[.]com
  • vatrobran[.]hr

According to the Russian cybersecurity firm, the trojanized software was delivered as standalone installers for the aforementioned programs as well as ZIP archives. These files include a malicious DLL read more about CPUID Breach Distributes STX RAT via Trojanized CPU-Z and HWMonitor Downloads.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *