Trusted Software Compromised: CPU-Z and HWMonitor Downloads Trojanized

Trusted Software Compromised: CPU-Z and HWMonitor Downloads Trojanized

Cyber Threat Intelligence reports a significant compromise targeting users seeking system diagnostic tools. Downloads of popular software like CPU-Z and HWMonitor, sourced directly from the vendor’s website (cpuid.com), were found to be trojanized. This means attackers successfully injected malicious code into legitimate software installers. Users downloading these tools between August 26th and September 6th, 2023, may have inadvertently installed malware alongside the intended system utilities. The compromised versions are believed to contain a backdoor or information-stealing malware.

This incident highlights a sophisticated attack vector that leverages the trust users place in official software sources. By compromising the vendor’s download portal, attackers bypassed typical security checks and directly delivered malicious payloads to unsuspecting users. The threat actors aimed to distribute a trojan, though specific details regarding its capabilities or propagation methods are still under investigation by Cyber Threat Intelligence. The affected software is widely used by IT professionals, gamers, and system administrators for hardware monitoring and performance analysis.

What This Means For You

  • Malware activity detected β€” review endpoint detection rules.
πŸ”Ž
Stay ahead of this threat Search threats by organization, set watchlist alerts, or get a weekly SIEM digest with detection rules matched to your vendors β€” inside Telegram.
Open Intel Bot β†’
Source & Attribution
Source PlatformTelegram
ChannelCyber Threat Intelligence
PublishedApril 13, 2026 at 13:59 UTC

This content was AI-rewritten and enriched by Shimi's Cyber World based on the original source. All intellectual property rights remain with the original author.

Believe this infringes your rights? Submit a takedown request.

Related coverage

Dutch Authorities Dismantle Botnet of 17 Million Infected Devices

Dutch authorities, in collaboration with the Dutch Politie and the National Cyber Security Center (NCSC), have successfully dismantled a massive botnet, according to The Hacker...

threat-intelvulnerabilitymalware
/SCW Vulnerability Desk /MEDIUM /⚑ 3 IOCs

FortiClient EMS Flaw Exploited to Deploy Credential Stealer

Threat actors are actively exploiting a critical, albeit patched, vulnerability in FortiClient Endpoint Management Server (EMS) deployments. This flaw is being leveraged to distribute credential-stealing...

threat-intelvulnerabilitymalwareidentity
/SCW Vulnerability Desk /MEDIUM /⚑ 2 IOCs /⚙ 3 Sigma

Gogs Zero-Day RCE Puts Self-Hosted Git Instances at Risk

An unpatched zero-day vulnerability in the Gogs self-hosted Git service allows attackers to achieve remote code execution (RCE) on internet-facing instances. BleepingComputer reports this critical...

threat-inteldata-breachmalwarevulnerability
/SCW Vulnerability Desk /HIGH /⚑ 2 IOCs /⚙ 3 Sigma