CPUID website served trojanised HWMonitor and CPU-Z installers
On 9 April 2026, community researchers found that the official CPUID website, home of the widely used HWMonitor and CPU-Z tools, was serving malicious installers through a redirected download link. Users downloading HWMonitor from the official page were redirected to a Cloudflare R2 storage bucket and received a file named HWiNFO_Monitor_Setup.exe, deliberately chosen to mimic the unrelated but legitimate HWiNFO64 product. The installer is a customised wrapped InnoSetup package of a kind commonly associated with malware, contains sandbox detection, and creates several persistent processes on execution. Analysis and VirusTotal scanning confirm the file as malicious. Similar reports have surfaced for CPU-Z downloads.
What this means for your organisation
These are small, free tools that operations staff and developers download without a second thought, usually in the middle of troubleshooting something else. Downloading from the vendor's own site is normally treated as safe, and here that exact channel failed. The impact lands on machines with elevated rights, which are precisely the machines an attacker wants.
Berigo recommends
- Search endpoint logs for HWiNFO_Monitor_Setup.exe and for HWMonitor or CPU-Z installations dated April.
- Treat any machine with a hit as compromised rather than merely suspicious.
- Maintain an internal, vetted set of tools for operations and development, so downloading from the web is not the default answer.
- Require signature and filename verification when installing tools on machines with administrative rights.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch