Signal

Hackers compromise CPUID downloads to distribute STX RAT malware

Evidence first: scan the strongest sources, then decide whether to go deeper.

Published 2026-04-13 09:52 UTCUpdated 2026-04-13 13:07 UTC
rss
malwarethreat_actorssecurity_tooling
Source links open
Source links and full evidence are open here. Archive history, compare-over-time, alerts, exports, API, integrations, and workflow are paid.
No card needed for the free brief.
Evidence trail (top sources)
top sources (2 domains)domains are deduped. counts indicate coverage, not truth.
2 top sources shown
Hackers hijacked CPUID downloads, served STX RAT to victims
Help Net Security · News · helpnetsecurity.com · 2026-04-13 13:07 UTC
limited source diversity in top sources
Overview

Between April 9 and April 10, a Russian-speaking threat actor compromised a secondary API on CPUID's website, replacing legitimate download links for CPU-Z and HWMonitor with trojanized versions distributing the STX RAT malware.

Score total
1.21
Momentum 24h
3
Posts
3
Origins
2
Source types
1
Duplicate ratio
0%
Why now
  • The CPUID compromise occurred recently, exposing users to STX RAT malware.
  • The incident underscores ongoing risks from supply chain attacks.
  • Fake Claude website distributing PlugX RAT shows continued exploitation of trusted brands.
Why it matters
  • Compromise of trusted software downloads can lead to widespread malware infections.
  • Supply chain attacks expose vulnerabilities in software distribution infrastructure.
  • Users and organizations must verify software integrity to avoid trojanized downloads.
LLM analysis
Topic mix: lowPromo risk: lowSource quality: medium
Recurring claims
  • CPUID's download links were replaced with trojanized versions distributing STX RAT malware between April 9 and April 10, 2026.
  • A fake Claude website was distributing PlugX RAT malware using DLL sideloading techniques.
How sources frame it
  • CPUID Contributor Samuel Demeulemeester: neutral
Consolidated multiple reports on CPUID compromise and related malware distribution for clarity.
All evidence
All evidence
Hackers hijacked CPUID downloads, served STX RAT to victims
Help Net Security · helpnetsecurity.com · 2026-04-13 13:07 UTC
CPUID Hacked to Serve Trojanized CPU-Z and HWMonitor Downloads
SecurityWeek · securityweek.com · 2026-04-13 10:52 UTC
Show filters & breakdown
Posts loaded: 0Publishers: 2Origin domains: 2Duplicates: -
Showing 2 / 0
Top publishers (this list)
  • Help Net Security (1)
  • SecurityWeek (1)
Top origin domains (this list)
  • helpnetsecurity.com (1)
  • securityweek.com (1)