MIT TRACE

MIT CTL Logo
Back to Main Dashboard

CPUID download infrastructure hijacked to distribute STX RAT

On 9 April 2026, attackers compromised a backend component used by CPUID's official website and replaced legitimate download destinations for CPU-Z, HWMonitor, HWMonitor Pro and PerfMonitor 2 with attacker-controlled packages. The trojanized downloads combined legitimate software components with a malicious DLL that ultimately deployed STX RAT. Kaspersky observed malicious redirects through 10 April and identified more than 150 infections, including organizations in retail, manufacturing, consulting, telecommunications and agriculture, with most observed infections in Brazil, Russia and China. Although CPUID's original signed binaries were not modified, compromise of the trusted vendor download path created a direct software-supply-chain data-integrity impact.

74

Estimated severity

74 / 100

93

Source reliability

93 / 100

Approximate Date

09/04/2026

Targeted Company

CPUID

Targeted Company Supply Chain Impact

  1. Distribution & Fulfillment

  2. Procurement & Sourcing

  3. Production & Manufacturing

  4. Sales (Retail & Ecommerce)

  5. Warehousing

  6. Service Delivery

  7. Unrecognized Impact

Supply Chain Relations

No information

Geographic Impact

Country Targeted Company

France

FRA

Other Affected Countries

Brazil

BRA

Russian Federation

RUS

Colombia

COL

Chile

CHL

Turkey

TUR

Spain

ESP

Germany

DEU

Italy

ITA

China

CHN

Target country

France

Affected countries

BrazilRussian FederationColombiaChileTurkeySpainGermanyFranceItalyChina

Impacted regions

No information

Operational Impact

Duration

No information

Financial impact (USD M)

No information

Impact types

Supply chain data integrity impact

Affected sectors

Technology & IT ServicesRetailManufacturingTelecommunicationsAgriculture, Forestry & FishingProfessional & Business Services

Affected departments

Information Technology

Attack Profile

Attack types

Software supply chain compromiseMalwareRemote access trojan

Attributed threat actors

No information

Sources

Please rotate your phone

MIT TRACE is optimized for landscape orientation on mobile.