Steam Workshop and Wallpaper Engine, creating risks of account theft and session hijacking
Malware Hidden in Animated Wallpapers on Steam
Kaspersky has detected a malware campaign using Steam Workshop and Wallpaper Engine to distribute malicious software disguised as animated wallpapers, posing risks of credential theft and session hijacking.
Global cybersecurity company Kaspersky has identified a new malware campaign targeting users of the popular gaming platform Steam. According to the company's researchers, cybercriminals are distributing malicious software disguised as animated wallpapers through Steam Workshop and Wallpaper Engine.
The investigation found that the primary targets were users in China and Russia. However, infections were also detected in Singapore, Germany, Vietnam, India and Canada.
Researchers said the attackers exploited a Wallpaper Engine feature that allows programs to run on Windows computers. Malware was concealed within wallpaper files or password-protected archives. Once users installed the files, the malicious code was activated.
One analyzed sample appeared to be a regular desktop game but secretly installed DarkKomet, a backdoor capable of stealing Steam account credentials and taking control of active user sessions.
The researchers also detected multiple malware families, including Lumma, Vidar and RenEngine. This suggests that several cybercriminal groups may be involved in the campaign.
Maxim Starodubov, a cybersecurity expert at Kaspersky, said trusted platforms can also be abused for malware distribution. He noted that attackers are leveraging users’ trust in legitimate and well-known platforms to reach large numbers of victims.
Kaspersky advised users to verify the identity and credibility of content creators before downloading applications or user-generated content, even from familiar platforms. The company also recommended using reliable cybersecurity solutions to detect and block potential threats.
Security experts further recommend avoiding suspicious downloads, enabling two-factor authentication, using strong passwords and keeping security software updated to reduce the risk of compromise.
//DBTech/RI/EK//





