Gamers beware: malicious wallpapers on Steam found stealing accounts
June 16, 2026, 11:18 a.m.
Description
Since late 2025, cybercriminals have been exploiting Wallpaper Engine, a popular live wallpaper application on Steam, to distribute malware through Steam Workshop. Attackers target primarily Chinese and Russian gamers by embedding malicious code within application wallpapers shared on the platform. These compromised wallpapers deliver various malware types including infostealers, backdoors, crypto miners, and ransomware. One analyzed sample dropped DarkKomet backdoor while hijacking Steam sessions to steal account credentials. The malware modifies system libraries to locate Steam installations and exfiltrate data to attacker-controlled servers. Compromised accounts are then used to upload additional malicious wallpapers. The diverse malware families suggest multiple independent hacking groups are exploiting this distribution method. Infected wallpapers received thousands of downloads before removal, with 89% of infections occurring in China.
Tags
Date
- Created: June 16, 2026, 9:50 a.m.
- Published: June 16, 2026, 9:50 a.m.
- Modified: June 16, 2026, 11:18 a.m.
Indicators
- fc586cad94e5a10dd5be6a6ae6096bd02dfbfd094365bec87e788ed0798d6f67
- 120.48.156.17
- 202.144.192.29
- http://brightly.to/download2/Themes2.zip
- http://202.144.192.29/download2/Themes2.zip
- https://www.dropbox.com/s/zhp1b06imehwylq/Synaptics.rar?dl=1
- https://docs.google.com/uc?id=0BxsMXGfPIZfSVzUyaHFYVkQxeFk&export=download
- http://202.144.192.29/audit.php
Additional Informations
- India
- British Indian Ocean Territory
- Hong Kong
- Germany
- Canada
- Singapore
- Russian Federation
- China