stroz
April 10, 2026, 12:35pm
1
Observable: CPUID Downloads with Malware
Observable Type: Supply Chain compromise (?)
Details: Users reporting getting a malware executable while downloading HWMonitor software from the official CPUID website
A discussion on Reddit from an everyday user, with some analysis in the comments: Reddit - Please wait for verification
Some press coverage: https://cybernews.com/security/cpuid-hwmonitor-hwinfo-cpuz-deliver-malware/
3 Likes
stroz
April 10, 2026, 12:38pm
2
User Hattix has this analysis :
Quick analysis…
Download link on https://www.cpuid.com/softwares/hwmonitor.html
goes to httpx://pub-45c2577dbd174292a02137c18e7b1b5a.r2.dev/hwmonitor/HWiNFO_Monitor_Setup.exe which is obviously unusual.
This has the description “Установка — HWiNFO Monitor, версия 1.63” in it. Now I’m pretty sure CPUID is based out of France, so the presence of Russian there is not great. The term “HWiNFO” is not right here either, it’s a completely different tool.
The file is built with a customised “wrapped” Innosetup often used by malware, making it difficult to extract. “Real” Hwmonitor just uses regular InnoSetup and can be extracted with simple and common tools.
Their site has been hacked is the simplest explanation.
1 Like
It’s apparently quite similar to this:
Per:
cpuid has been compromised, most downloads are serving a rat+infostealer as we speak, make sure you didn't get hit
edit 04:53 utc: the website seems to be mostly back to normal, pages for perfmonitor and powermax still bundle malware, but the links...
VT links for samples:
1 Like
IoCs
(Per VXUG)
Portable HWMonitor Installer (1.63):
3d91f442ddc055e19e3710482e1605836c799249dacd43d99843257a3affd2d2
Fake CRYPTBASE.dll:
a27df06c7167eced1ddaeb8adccaa5f60500f52bc7030389eed2a0903cdf8286
Trojanized HWMonitor:
02db6764d1f13b837b0a525e5931bdbc67e7a2a4d071e849c7e087255d4a2d5b
Can't remember what this file did:
4547f3c7854413f9ae0806c51564684b796399bea0511a8b6c4d63a136c8ad56
Can't remember what this file did (1):
f633b48d5281709bcf3b1d8f54703792e51bb38ab507e9caa9c2fbe79b78aa53
Can't remember what this file did (2):
058f45b11fdd43ef51571577ec2ed9bcabe039a6615d05900aeb3655e9cec7e9
.cs file:
788d3f14ff6a701b114e0b40990379c0302e26c1bbbce22a7ee5c872c7df1d1f
.NET assembly:
47c17003d58cd609bff8ab788b51803b3b0de0648b40cd4e5591948298914753
C2:
https://welcome[.]supp0v3[.]com/d/callback
1 Like
Great work @stroz ! I was just wondering if we need a thread, and here it is! It’s working!
2 Likes
Powermax is also in the mix, it seems.
Do we like these? Do we care?
1 Like