Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Microsoft August 2026 Patch Tuesday fixes 394 flaws, including 3 zero-days
August 11, 2026
Critical Zoom Zero-Click Flaws Let Attackers Hijack User Devices
August 11, 2026
DEF CON Attendees Broadcast Fake Wi-Fi Network on Flight
August 11, 2026
Home/CyberSecurity News/Critical Steam Bug in Workshop Wallpapers Hijacks User Sessions
CyberSecurity News

Critical Steam Bug in Workshop Wallpapers Hijacks User Sessions

Key Takeaways Threat actors have been exploiting Valve’s Steam Workshop since late 2025 by embedding malware in Wallpaper Engine application wallpapers. The malicious wallpapers install...

Marcus Rodriguez
Marcus Rodriguez
June 17, 2026 3 Min Read
57 0

Key Takeaways

  • Threat actors have been exploiting Valve’s Steam Workshop since late 2025 by embedding malware in Wallpaper Engine application wallpapers.
  • The malicious wallpapers install backdoors, infostealers, and crypto miners, ultimately hijacking active Steam user sessions.
  • The primary targets are users in China (89%), but the attack method is adaptable for a global audience.
  • Valve has removed identified malicious content, but new malicious uploads continue to appear, requiring user vigilance.

Steam Workshop Becomes Conduit for Session Hijacks via Malicious Wallpapers

A comprehensive report from Kaspersky has revealed a persistent campaign by threat actors exploiting Valve’s Steam Workshop since late 2025. Attackers are leveraging the popular Wallpaper Engine application to distribute malware embedded within custom wallpapers, leading to the compromise of active Steam user sessions. Victims are subsequently infected with various malicious payloads, including backdoors, infostealers, and cryptocurrency miners. Kaspersky’s analysis indicates that a significant 89% of the targeted users reside in China.

Table Of Content

  • Key Takeaways
  • Steam Workshop Becomes Conduit for Session Hijacks via Malicious Wallpapers
  • Exploitation Methods and Attack Chain
  • What You Should Do

Wallpaper Engine, a widely used Steam application, allows users to customize their Windows desktops with animated and interactive backgrounds. Its immense popularity, evidenced by nearly a million reviews and approximately 100,000 daily active users, presents a substantial attack surface that threat actors have eagerly exploited.

The application supports diverse wallpaper formats, including videos, scenes, web pages, and application wallpapers. It is this last category that attackers have specifically targeted. Application wallpapers function as standalone executable programs that run as the user’s desktop background, meaning that launching one is functionally equivalent to executing an arbitrary program on the system.

Given that anyone can freely publish content to the Steam Workshop, attackers have uploaded weaponized wallpapers disguised as legitimate games, widgets, and desktop utilities. Kaspersky researchers identified dozens of these malicious wallpapers, many of which had already accumulated thousands, and in some cases tens of thousands, of downloads before their detection.

Exploitation Methods and Attack Chain

Threat actors employed two primary methods for distributing their malicious wallpapers. The first involved bundling malicious executables, DLLs, or scripts directly within the wallpaper archive alongside the visible application.

The second method involved concealing the malware within a password-protected archive. Victims were either socially engineered into manually entering the password, or a script automatically extracted it from the archive’s filename or an accompanying JSON configuration file.

Upon a victim launching an infected wallpaper, the attack executes silently and immediately. A backdoor, identified as Synaptics.exe and belonging to the DarkKomet remote access trojan family, is dropped into C:ProgramDataSynaptics.

Concurrently, a secondary executable named ._cache_GAME1.exe is launched. This executable loads the visible game (e.g., NTRaholic) to maintain the illusion of a legitimate wallpaper while simultaneously installing a modified version of AggregatorHost.dll, which is laden with a malicious payload.

This tampered system library then scans the host machine for the Steam client and hijacks the user’s active session. The stolen session data is subsequently exfiltrated to an attacker-controlled command-and-control server located at hxxp://120.48.156[.]17/ey.php.

With a live Steam session successfully captured, the attackers gain full account access. This allows them to upload additional malicious wallpapers directly to the Steam Workshop, thereby perpetuating the infection cycle and expanding their reach.

Beyond the DarkKomet backdoor, Kaspersky’s investigation uncovered a diverse array of payloads. These included the Lumma and Vidar infostealers, the RenEngine loader, ransomware droppers, and various botnet loaders. The wide variety of tools suggests that multiple independent threat groups are leveraging this exploitation technique, rather than a single, coordinated actor. Key Kaspersky detection verdicts associated with this campaign include:

  • HEUR:Trojan-PSW.Win32.gen
  • HEUR:Backdoor.Win32.DarkKomet
  • Trojan-Dropper.Python.Agent
  • HEUR:Trojan-Ransom.Win32.Gen.gen
  • PDM:Trojan.Win32.Generic

As noted, China accounts for 89% of the malicious download attempts, with the wallpaper art styles and titles explicitly tailored for Chinese-speaking users. Russia follows with 5.5% of the victim pool, while Singapore (1.4%), Hong Kong (0.9%), Germany (0.9%), Vietnam (0.9%), India (0.5%), and Canada (0.5%) also saw compromised users. Researchers caution that the campaign’s underlying template could easily be adapted to target any global audience.

What You Should Do

  • Avoid downloading application-type wallpapers from unknown or unverified creators on the Steam Workshop.
  • Scan all downloaded Workshop content with a reputable, up-to-date antivirus solution before applying it to your system.
  • Enable Steam Guard and two-factor authentication (2FA) on your Steam account to significantly limit the impact of a potential session hijack.
  • Regularly monitor your system processes for unexpected executables, such as Synaptics.exe, or unsigned DLLs loading from directories like ProgramData.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitHackerMalwarePatchransomwareThreat

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

Detecting macOS Malware with Network Monitoring and Behavioral Analysis

Next Post

Threat Actors Leverage OpenAI Codex and Claude for Exploitation and Data Exfiltration

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
LLM API Vulnerability Exposes AI Model Reasoning, Poses Data Risk
August 11, 2026
Critical SAP Vulnerabilities Allow Code Injection, Memory Corruption
August 11, 2026
Critical Ivanti Endpoint Manager CVEs Let Remote Attackers Crash Agent Service
August 11, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us