Signal
Hackers compromise CPUID downloads to distribute STX RAT malware
Evidence first: scan the strongest sources, then decide whether to go deeper.
Published 2026-04-13 09:52 UTCUpdated 2026-04-13 13:07 UTC
rss
malwarethreat_actorssecurity_tooling
Source links open
Source links and full evidence are open here. Archive history, compare-over-time, alerts, exports, API, integrations, and workflow are paid.
No card needed for the free brief.
Evidence trail (top sources)
top sources (2 domains)domains are deduped. counts indicate coverage, not truth.2 top sources shown
limited source diversity in top sources
Overview
Between April 9 and April 10, a Russian-speaking threat actor compromised a secondary API on CPUID's website, replacing legitimate download links for CPU-Z and HWMonitor with trojanized versions distributing the STX RAT malware.
Score total
1.21
Momentum 24h
3
Posts
3
Origins
2
Source types
1
Duplicate ratio
0%
Why now
- The CPUID compromise occurred recently, exposing users to STX RAT malware.
- The incident underscores ongoing risks from supply chain attacks.
- Fake Claude website distributing PlugX RAT shows continued exploitation of trusted brands.
Why it matters
- Compromise of trusted software downloads can lead to widespread malware infections.
- Supply chain attacks expose vulnerabilities in software distribution infrastructure.
- Users and organizations must verify software integrity to avoid trojanized downloads.
LLM analysis
Topic mix: lowPromo risk: lowSource quality: medium
Recurring claims
- CPUID's download links were replaced with trojanized versions distributing STX RAT malware between April 9 and April 10, 2026.
- A fake Claude website was distributing PlugX RAT malware using DLL sideloading techniques.
How sources frame it
- CPUID Contributor Samuel Demeulemeester: neutral
Consolidated multiple reports on CPUID compromise and related malware distribution for clarity.
All evidence
All evidence
Hackers hijacked CPUID downloads, served STX RAT to victims
Help Net Security · helpnetsecurity.com · 2026-04-13 13:07 UTC
CPUID Hacked to Serve Trojanized CPU-Z and HWMonitor Downloads
SecurityWeek · securityweek.com · 2026-04-13 10:52 UTC
Show filters & breakdown
Posts loaded: 0Publishers: 2Origin domains: 2Duplicates: -
Showing 2 / 0
Top publishers (this list)
- Help Net Security (1)
- SecurityWeek (1)
Top origin domains (this list)
- helpnetsecurity.com (1)
- securityweek.com (1)