CPU-Z and HWMonitor Hacked
Key point
CPUID's official download path was compromised, distributing malware through CPU-Z and HWMonitor.
Details
CPUID's download path was compromised for about 6 hours, during which CPU-Z, HWMonitor, HWMonitor Pro, and PerfMonitor downloads from the official site were replaced with malicious files. The original signed files themselves were not touched, but the distribution links were tampered with, resulting in a setup where users received fake installers.
The downloaded files were disguised under names like HWiNFO_Monitor_Setup, and running them displayed a Russian-language installer and an Inno Setup wrapper. Kaspersky confirmed DLL sideloading using CRYPTBASE.dll alongside a legitimate EXE, with the final payload being STX RAT.
The attack window is estimated to be 2026-04-09 15:00 UTC to 2026-04-10 10:00 UTC, and the affected versions are as follows.
- CPU-Z 2.19
- HWMonitor Pro 1.57
- HWMonitor 1.63
- PerfMonitor 2.04
Kaspersky estimated that more than 150 people downloaded the malicious variant, with victims including retail, manufacturing, consulting, telecom, and agriculture organizations in Brazil, Russia, and China. Analysis showed the attackers used the same C2 and configuration as last March's fake FileZilla campaign, and CPUID has now fixed the issue and is providing clean versions.
This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.
Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.