# Security Week 2616: взлом сайта CPU-Z и HWMonitor

DevFeed: [Security Week 2616: взлом сайта CPU-Z и HWMonitor](<https://devfeed.tech/articles/security-week-2616-cpu-z-hwmonitor-23066.md>)

Original publisher: [Read original article](<https://habr.com/ru/companies/kaspersky/articles/1022908/>)

Author: Kaspersky\_Lab ("Лаборатория Касперского")

Published: 2026-04-13T18:39:55Z

Content type: news

Language: ru

Sources: ["Лаборатория Касперского" RU](<https://devfeed.tech/sources/ru-2.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [cpu](<https://devfeed.tech/topics/cpu.md>), [anthropic](<https://devfeed.tech/topics/anthropic.md>), [Claude](<https://devfeed.tech/topics/claude.md>), [FFmpeg (Fast Forward Moving Picture Experts Group)](<https://devfeed.tech/topics/ffmpeg.md>), [Firefox](<https://devfeed.tech/topics/firefox.md>), [Nvidia](<https://devfeed.tech/topics/nvidia.md>), [Unix](<https://devfeed.tech/topics/unix.md>)

Tags: [amazon](<https://devfeed.tech/tags/amazon.md>), [anthropic](<https://devfeed.tech/tags/anthropic.md>), [claude](<https://devfeed.tech/tags/claude.md>), [claude-mythos](<https://devfeed.tech/tags/claude-mythos.md>), [cpu](<https://devfeed.tech/tags/cpu.md>), [cpu-z](<https://devfeed.tech/tags/cpu-z.md>), [firefox](<https://devfeed.tech/tags/firefox.md>), [hwmonitor](<https://devfeed.tech/tags/hwmonitor.md>), [mozilla](<https://devfeed.tech/tags/mozilla.md>), [mozilla-firefox](<https://devfeed.tech/tags/mozilla-firefox.md>), [mythos](<https://devfeed.tech/tags/mythos.md>), [nvidia](<https://devfeed.tech/tags/nvidia.md>), [security](<https://devfeed.tech/tags/security.md>), [tag-9fe8963de219](<https://devfeed.tech/tags/tag-9fe8963de219.md>), [unix](<https://devfeed.tech/tags/unix.md>)

## AI overview

This Russian-language Security Week roundup reports that cpuid.com was compromised for about 18 hours, causing malicious downloads of CPU-Z, HWMonitor, and PerfMonitor installers that included the CRYPTBASE.DLL malware component and ultimately delivered STX RAT. It also discusses Anthropic's Claude Mythos model and reported vulnerability discovery and exploitation capabilities, including a 72% exploitation rate for Mozilla Firefox vulnerabilities.

## Source excerpt

9 апреля был взломан веб-сайт cpuid.com, с которого распространяются популярные утилиты CPU-Z, HWMonitor и PerfMonitor. В течение примерно 18 часов ссылки на загрузку этих утилит были подменены на вредоносные. Специалисты "Лаборатории Касперского" провели анализ данной кибератаки, в ходе которой на компьютеры жертв устанавливалось ПО для кражи персональных данных. Модифицированные инсталляторы содержали оригинальный легитимный дистрибутив соответствующей утилиты и вредоносную библиотеку CRYPTBASE.DLL. Она отвечает за подключение к командному серверу и запуск следующей стадии атаки. Интересным моментом является тот факт, что организаторы атаки повторно использовали командный сервер, который ранее был замечен в совсем другой атаке: в марте он был задействован при распространении поддельной версии популярного FTP-клиента FileZilla. Читать далее