← Blog

CPUID Download Site Watering Hole: Trojanized CPU-Z and HWMonitor

Share on X

Security researchers described a watering-hole attack on CPUID’s public download path: a breached side API redirected some CPU-Z and HWMonitor fetches to malicious archives with DLL side-loading and STX RAT stages—not a replacement of vendor-signed source code.

Canonical record: CPUID 2026 on BreachHistory.

Sources: Kaspersky Securelist, Neowin