Full Breakdown
Malware Campaign on Steam Workshop Exploits Wallpaper Engine
6/17/2026, 12:43:23 PM
Malware Campaign on Steam Workshop
Since late 2025, threat actors have uploaded wallpaper packages to the Steam Workshop that embed hidden scripts or executables. When a user applies such a wallpaper in Wallpaper Engine, the code runs automatically, delivering backdoors, infostealers, ransomware, or crypto-miner components. The campaign targets users in China and Russia.
Workshop Overview
Steam Workshop is a user-generated content hub for mods, skins, maps, and wallpapers. Wallpaper Engine, a live-wallpaper app on Steam, reports about 100 000 daily active users and one million reviews. The app supports video, scene, web-page, and “application” wallpapers, the latter allowing arbitrary code execution.
Delivery Methods
Researchers identified two packaging approaches. Some archives bundle the wallpaper with malicious EXE, DLL, or script files. Others use password-protected archives, with passwords hidden in file names or JSON metadata. A sample drops Synaptics.exe (DarkKomet family) and a modified AggregatorHost.dll that harvests Steam credentials and sends them to hxxp://120.48.156[.]17/ey.php. Observed malware families include DarkKomet, Lumma, Vidar infostealers, and the RenEngine loader.
Geographic Reach
Malicious wallpapers have been downloaded thousands to tens of thousands of times. Security logs show 89 % of malicious attempts originated in China, 5.5 % in Russia, with smaller shares in Singapore (1.4 %), Hong Kong (0.9 %), Germany (0.9 %), Vietnam (0.9 %), India (0.5 %) and Canada (0.5 %). Variety of tools indicates multiple independent hacking groups.
Consequences
Execution can hijack Steam accounts, encrypt files with ransomware, or install hidden crypto-miners that degrade performance. Compromised accounts are later used to upload further malicious wallpapers, expanding the infection chain.
Responses
Kaspersky researchers disclosed the campaign and detection signatures. The Steam team removed the identified malicious wallpapers and related links from the Workshop before the report’s release. Kaspersky security products can block the payloads, and users are advised to scan wallpapers with antivirus software before activation.
Criticism & Opposition
Security analysts warn against trust of community content. Recommended safeguards include reviewing creator profiles, reading recent comments, avoiding wallpapers that request external downloads, and keeping an active antivirus solution such as Windows Security enabled.
Gaps
Public sources do not disclose total number of malicious wallpapers discovered, nor do they attribute activity to specific threat groups beyond inference of multiple actors.
Quotes
- “Think twice before downloading user-generated content.” — MakeUseOf author
- “Once launched, there’s absolutely nothing to trigger your suspicion.” — Kaspersky researcher, Securelist
- “Right now, the primary targets are gamers in China.” — Kaspersky researcher, Securelist
- “Our investigation proves that even trusted platforms like the Steam Workshop aren’t completely safe from malware.” — Kaspersky researcher, Securelist
Outlook
Analysts caution that the same technique could be repurposed for campaigns targeting other regions. Monitoring of Steam Workshop uploads and user vigilance remain essential to mitigate further infections.
