Hackers are using Steam's Wallpaper Engine to distribute malware that can steal your logins

Your Wallpaper Engine downloads could be running malware right now. Kaspersky found dozens of infected Steam Workshop packages deploying ransomware.

Hackers are using Steam's Wallpaper Engine to distribute malware that can steal your logins
Comment IconFacebook IconX IconReddit Icon
Tech Reporter
Published
1 minute & 45 seconds read time
TL;DR: Hackers are embedding malware in Steam Wallpaper Engine's application wallpapers, which are executable files, to steal Steam accounts and install malicious software like DarkKomet, Lumma, and ransomware. Dozens of infected packages were found, mainly targeting China and Russia, with victims worldwide. Users should scan for malware, change passwords, and enable Steam Guard.
Voice: Hassam Nasir
0:00 / 2:59
Use left and right arrow keys to seek audio.

If you use Wallpaper Engine, now's a good time to pay attention. Kaspersky researchers have discovered that hackers are hiding malware inside wallpaper packages on the Steam Workshop, using them to steal Steam accounts and install additional malicious software on victims' PCs. The bad actors are exploiting the popularity of Steam's Wallpaper Engine to funnel users to the Workshop, from which they distribute malware.

Here's why this works so well: unlike a regular JPEG or PNG, Wallpaper Engine's "application wallpapers" are actual Windows executables that run on your system like any other program. That makes them a pretty convenient hiding spot for bad actors. The Wallpaper Engine also houses wallpapers in other formats, but it is these "application wallpapers' that are the primary source of the attack.

Once you launch one of these infected wallpapers, it drops a backdoor onto your system, part of the DarkKomet malware family, and quietly installs a modified system library designed to hunt down your Steam credentials and hijack your active session. After taking over your Steam account, the attackers use it to upload additional infected wallpapers, perpetuating the cycle by compromising more PCs.

Observed attack flow of the malware
Observed attack flow of the malware

Kaspersky also found other malware families in the mix, including Lumma and Vidar infostealers, crypto miners, botnet loaders, and ransomware strains. This suggests that multiple threat actors were abusing the same Wallpaper Engine vector. Kaspersky says the attacks were likely carried out by independent threat actors rather than a single group.

One of the infected wallpapers
One of the infected wallpapers

Dozens of compromised packages were found on Steam Workshop, some of which had already been downloaded tens of thousands of times. China and Russia were the primary targets, but victims were also identified in Germany, Singapore, Canada, Hong Kong, and India. Steam has since removed the malicious wallpapers Kaspersky flagged, but researchers warn that new ones are likely already on the way.

Therefore, you should treat this less like a closed incident and more like an ongoing threat. If you've downloaded interactive or application-type wallpapers from unknown creators recently, run a full malware scan and change your Steam password. Enabling Steam Guard if you haven't already is also a good move. And going forward, stick to wallpapers from creators with a decent track record and community reviews.

Photo of the Engine Wallpaper HD

Best Deals: Engine Wallpaper HD

* Prices may be inaccurate. As an Amazon Associate, we earn from qualifying purchases. We earn affiliate commission from any Newegg or PCCG sales.

News Source:kaspersky.com

Tech Reporter

Email IconX IconLinkedIn Icon

Hassam is a veteran tech journalist and editor with over eight years of experience embedded in the consumer electronics industry. His obsession with hardware began with childhood experiments involving semiconductors, a curiosity that evolved into a career dedicated to deconstructing the complex silicon that powers our world. From benchmarking PC internals to stress-testing flagship CPUs and GPUs, Hassam specializes in translating high-level engineering into deep, unbiased insights for the enthusiast community.

Stay Updated

Follow TweakTown for breaking tech news, reviews, and daily updates.

Add TweakTown as a preferred source on GoogleFind TweakTown on Apple News
Newsletter Subscription