{
  "name": "CPU-Z & HWMonitor, cpuid.com, Watering Hole Attack",
  "slug": "cpu-z-hwmonitor-cpuidcom-watering-hole-attack",
  "description": "On April 9, 2026, the cpuid.com website was compromised in a watering hole attack lasting approximately 19 hours. Download URLs for legitimate system administration tools CPU-Z, HWMonitor, HWMonitor Pro, and Perfmonitor 2 were replaced with links to malicious sites distributing trojanized versions. The malicious installers contained legitimate signed executables paired with DLL files named CRYPTBASE.dll that exploited DLL sideloading for C2 communication and payload delivery. Attackers reused infrastructure and code from a March 2026 fake FileZilla campaign, including the STX RAT as the final payload. Over 150 victims were identified globally, primarily individuals but including organizations in retail, manufacturing, consulting, telecommunications and agriculture sectors. The attack demonstrated poor operational security with reused indicators enabling rapid detection.",
  "published": "2026-04-13T06:47:01+00:00",
  "created_at": "2026-04-13T06:47:01+00:00",
  "modified_at": "2026-04-13T07:16:42+00:00",
  "created_at_opencti": "2026-04-13T06:47:01+00:00",
  "author": "",
  "confidence": null,
  "report_types": [],
  "labels": [],
  "tags": [
    "2026-04-13",
    "cpu-z",
    "cpuid.com",
    "cryptbase.dll",
    "dll sideloading",
    "hwmonitor",
    "stx rat",
    "supply chain compromise",
    "watering hole attack"
  ],
  "related_entities": {
    "observables": [
      {
        "id": "",
        "name": "https://welcome.supp0v3.com/d/callback"
      },
      {
        "id": "",
        "name": "https://welcome.supp0v3.com"
      },
      {
        "id": "",
        "name": "https://transitopalermo.com/config/hwmonitor/hwmonitor_1.63.zip"
      },
      {
        "id": "",
        "name": "https://transitopalermo.com/config/hwmonitor-pro/hwmonitorpro_1.57_setup.exe"
      },
      {
        "id": "",
        "name": "https://vatrobran.hr/en-GB/info/cpu-z/cpu-z_2.19-en.zip"
      },
      {
        "id": "",
        "name": "https://vatrobran.hr/en-GB/info/hwmonitor-pro/HWMonitorPro_1.57_Setup.exe"
      },
      {
        "id": "",
        "name": "https://vatrobran.hr/en-gb/info/hwmonitor/hwinfo_monitor_setup.exe"
      },
      {
        "id": "",
        "name": "https://cahayailmukreatif.web.id/sw-content/template/hwmonitor/hwinfo_monitor_setup.exe"
      },
      {
        "id": "",
        "name": "https://vatrobran.hr/en-GB/info/hwmonitor/hwmonitor_1.63.zip"
      },
      {
        "id": "",
        "name": "https://transitopalermo.com/config/hwmonitor/HWiNFO_Monitor_Setup.exe"
      },
      {
        "id": "",
        "name": "http://welcome.supp0v3.com/d/callback"
      },
      {
        "id": "",
        "name": "66ad4aaf260a5173d8eaa14db52629fd361add8b772f6a4bcc5c10328f0cc3c0"
      },
      {
        "id": "",
        "name": "1da87f0b8f820f4d4ef71c54c239f176bb2af6f18666cbf5b2433ddc4f87e711"
      },
      {
        "id": "",
        "name": "3e791c88d49ac569bc130fc9f41bd7422b4fd24f32458e11e890647478005a7f"
      },
      {
        "id": "",
        "name": "49685018878b9a65ced16730a1842281175476ee5c475f608cadf1cdcc2d9524"
      },
      {
        "id": "",
        "name": "eefc0f986dd3ea376a4a54f80ce0dc3e6491165aefdd7d5d6005da3892ce248f"
      }
    ],
    "malware": [
      {
        "id": "legacy:malware:3ab3a3e29f83552f",
        "name": "STX RAT",
        "slug": "stx-rat"
      },
      {
        "id": "legacy:malware:78281379cead1e77",
        "name": "CRYPTBASE.dll",
        "slug": "cryptbasedll"
      }
    ],
    "attack_patterns": [
      {
        "id": "c473a756-355a-42ad-a0df-cd3a8fa006d1",
        "name": "T1057"
      },
      {
        "id": "6ccd4566-e15e-40cf-b7df-4a3f737ce5cd",
        "name": "T1036.005"
      },
      {
        "id": "32817170-4c07-427e-b8a5-80a733ae2550",
        "name": "T1497"
      },
      {
        "id": "c3af9fd7-d307-4df4-9220-cc627938fb85",
        "name": "T1055"
      },
      {
        "id": "c9ee9b30-ba84-4c24-95e9-e8242d42af3f",
        "name": "T1071.001"
      },
      {
        "id": "29398669-98ed-4766-9dac-f9632f7175ff",
        "name": "T1518"
      },
      {
        "id": "dc17cbbd-40d8-43cf-b3cf-50d1276db2c7",
        "name": "T1016"
      },
      {
        "id": "196f2a64-c55b-47a6-8e38-beb76ba700b6",
        "name": "T1204.002"
      },
      {
        "id": "97d377d8-89c7-48f8-a79f-0f48bd60df74",
        "name": "T1005"
      },
      {
        "id": "0c836307-129e-4ff7-a532-180c633cacba",
        "name": "T1027"
      },
      {
        "id": "3be1a227-bbd0-4e76-9422-40e4078224f9",
        "name": "T1007"
      },
      {
        "id": "9b6064e6-a05b-4e95-baf5-34d180bc9221",
        "name": "T1059"
      },
      {
        "id": "e8422fc8-8365-4a6a-a556-d6ec16cb4e5d",
        "name": "T1574.002"
      },
      {
        "id": "5999052b-e9ae-49e8-9235-d9bf975c22af",
        "name": "T1547.001"
      },
      {
        "id": "5b7c66d1-0466-4ba7-af6f-eb82c2f9d05b",
        "name": "T1033"
      },
      {
        "id": "fe6f2946-a01e-460c-9636-8c48b45dd0e6",
        "name": "T1189"
      },
      {
        "id": "45082a8e-9c79-470e-ad1b-decac7188e8f",
        "name": "T1083"
      },
      {
        "id": "70616b2f-4019-4963-b758-5d9f6f20e201",
        "name": "T1082"
      },
      {
        "id": "ccb28547-a340-4193-a5d9-69222f3d5051",
        "name": "T1049"
      },
      {
        "id": "fa3b8b48-d97c-4242-83a6-07d435a5a79e",
        "name": "T1041"
      }
    ],
    "others": [
      {
        "id": "",
        "name": "Brazil"
      },
      {
        "id": "",
        "name": "Russian Federation"
      },
      {
        "id": "",
        "name": "China"
      },
      {
        "id": "",
        "name": "Agriculture and agribusiness"
      },
      {
        "id": "",
        "name": "Manufacturing"
      },
      {
        "id": "",
        "name": "Telecommunications"
      },
      {
        "id": "",
        "name": "Retail (distribution)"
      },
      {
        "id": "",
        "name": "welcome.supp0v3.com"
      },
      {
        "id": "",
        "name": "vatrobran.hr"
      },
      {
        "id": "",
        "name": "cahayailmukreatif.web.id"
      },
      {
        "id": "",
        "name": "transitopalermo.com"
      }
    ]
  },
  "external_refs": [
    "https://otx.alienvault.com/pulse/69dcad85f21975a887da9066",
    "https://securelist.com/tr/cpu-z/119365/"
  ]
}