Updated
Updated · Panda Security · Jul 22
Hackers Spread 5 Malware Types via Steam Workshop Wallpapers, Threatening Thousands of Users
Updated
Updated · Panda Security · Jul 22

Hackers Spread 5 Malware Types via Steam Workshop Wallpapers, Threatening Thousands of Users

2 articles · Updated · Panda Security · Jul 22

Summary

  • Thousands or even tens of thousands of Steam users may have downloaded malicious Wallpaper Engine uploads before Valve removed the identified files.
  • The campaign abused Wallpaper Engine's “application wallpaper” format, which can run Windows executables, letting attackers hide malware in wallpaper bundles or password-protected archives that looked like normal community content.
  • Researchers found DarkKomet backdoors, Lumma and Vidar infostealers, crypto miners, botnet loaders, RanEngine and ransomware, indicating multiple criminal groups used the same distribution method.
  • Stolen Steam credentials can be used to hijack inventories, scam friends and repost malware from trusted accounts, while the tactic remains viable because new Workshop uploads can quickly replace removed files.
  • Users are advised to avoid untrusted application wallpapers, scan downloads, keep antivirus updated and enable two-factor authentication because Steam Workshop's trust-based model still leaves the channel exposed.

Insights

How did Steam Workshop wallpapers become a stealth malware pipeline for stealing accounts, mining crypto, and spreading ransomware?
Why do stolen Steam accounts and gaming data make trusted workshop content such an attractive target for cybercriminals?
If a wallpaper can run code, should gaming platforms treat community uploads like software instead of harmless customization?