Logan Peña
3.3K posts

Logan Peña
@LoganPenaa
Sales Executive an PC Tuner @StinceBuilt | Co-Owner StallionSupps https://t.co/D7xLM8amF9


Mr. Titus Tech is correct. cpuid-dot-com is indeed delivering malware right now. As I began poking this with I stick I discovered this is not your typical run-of-the-mill malware. This malware is deeply trojanized, distributes from a compromised domain (cpuid-dot-com), performs file masquerading, is multi-staged, operates (almost) entirely in-memory, and uses some interesting methods to evade EDRs and/or AVs such as proxying NTDLL functionality from a .NET assembly. The C2 domain present in one of the binaries is a clear IoC. This is the same Threat Group who was masquerading FileZilla in early March, 2026. They've been busy.



Woke up to my pc doing this.😭






















