CPUID Breach Distributes STX RAT via Trojanized CPU-Z and HWMonitor Downloads

2026-04-13T01:24:14Z61b7a2d2d6f39be29c6a254ce74c0d0bbee505bfc322fc14b5939b4ea8d82093
APT28DockerEngageLab SDKGlassWormIoT botnetRCESDK vulnerabilitySTX RATactive exploitationbackdoorbrowser securitycloud misconfigurationcryptomining botnetidentity/IAMlaw-enforcement surveillancemalicious browser/IDE extensionmalwarenation-state activitypackage-repository poisoningsupply-chain compromisetrojanized installerszero-day

What happened

A batch of high-impact security events reported by The Hacker News: CPUID.com was briefly compromised to distribute trojanized CPU‑Z and HWMonitor installers delivering the STX RAT; Adobe released emergency updates for an actively exploited Acrobat Reader flaw (CVE-2026-34621); a critical Marimo pre-authenticated RCE (CVE-2026-39987, CVSS 9.3) was exploited within 10 hours of disclosure; and Docker Engine has a high-severity AuthZ bypass (CVE-2026-34040). Additional notable incidents include a GlassWorm campaign using a Zig-based dropper to infect developer IDEs, a backdoored Smart Slider 3Pro

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
61b7a2d2d6f39be29c6a254ce74c0d0bbee505bfc322fc14b5939b4ea8d82093
Enrichment time
2026-04-13T01:24:14Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · CPUID Breach Distributes STX RAT via Trojanized CPU-Z and HWMonitor Downloads · Baitaphish