Critical Steam Bug in Workshop Wallpapers Hijacks User Sessions
Key Takeaways Threat actors have been exploiting Valve’s Steam Workshop since late 2025 by embedding malware in Wallpaper Engine application wallpapers. The malicious wallpapers install...
Key Takeaways
- Threat actors have been exploiting Valve’s Steam Workshop since late 2025 by embedding malware in Wallpaper Engine application wallpapers.
- The malicious wallpapers install backdoors, infostealers, and crypto miners, ultimately hijacking active Steam user sessions.
- The primary targets are users in China (89%), but the attack method is adaptable for a global audience.
- Valve has removed identified malicious content, but new malicious uploads continue to appear, requiring user vigilance.
Steam Workshop Becomes Conduit for Session Hijacks via Malicious Wallpapers
A comprehensive report from Kaspersky has revealed a persistent campaign by threat actors exploiting Valve’s Steam Workshop since late 2025. Attackers are leveraging the popular Wallpaper Engine application to distribute malware embedded within custom wallpapers, leading to the compromise of active Steam user sessions. Victims are subsequently infected with various malicious payloads, including backdoors, infostealers, and cryptocurrency miners. Kaspersky’s analysis indicates that a significant 89% of the targeted users reside in China.
Table Of Content
Wallpaper Engine, a widely used Steam application, allows users to customize their Windows desktops with animated and interactive backgrounds. Its immense popularity, evidenced by nearly a million reviews and approximately 100,000 daily active users, presents a substantial attack surface that threat actors have eagerly exploited.
The application supports diverse wallpaper formats, including videos, scenes, web pages, and application wallpapers. It is this last category that attackers have specifically targeted. Application wallpapers function as standalone executable programs that run as the user’s desktop background, meaning that launching one is functionally equivalent to executing an arbitrary program on the system.
Given that anyone can freely publish content to the Steam Workshop, attackers have uploaded weaponized wallpapers disguised as legitimate games, widgets, and desktop utilities. Kaspersky researchers identified dozens of these malicious wallpapers, many of which had already accumulated thousands, and in some cases tens of thousands, of downloads before their detection.
Exploitation Methods and Attack Chain
Threat actors employed two primary methods for distributing their malicious wallpapers. The first involved bundling malicious executables, DLLs, or scripts directly within the wallpaper archive alongside the visible application.
The second method involved concealing the malware within a password-protected archive. Victims were either socially engineered into manually entering the password, or a script automatically extracted it from the archive’s filename or an accompanying JSON configuration file.
Upon a victim launching an infected wallpaper, the attack executes silently and immediately. A backdoor, identified as Synaptics.exe and belonging to the DarkKomet remote access trojan family, is dropped into C:ProgramDataSynaptics.
Concurrently, a secondary executable named ._cache_GAME1.exe is launched. This executable loads the visible game (e.g., NTRaholic) to maintain the illusion of a legitimate wallpaper while simultaneously installing a modified version of AggregatorHost.dll, which is laden with a malicious payload.
This tampered system library then scans the host machine for the Steam client and hijacks the user’s active session. The stolen session data is subsequently exfiltrated to an attacker-controlled command-and-control server located at hxxp://120.48.156[.]17/ey.php.
With a live Steam session successfully captured, the attackers gain full account access. This allows them to upload additional malicious wallpapers directly to the Steam Workshop, thereby perpetuating the infection cycle and expanding their reach.
Beyond the DarkKomet backdoor, Kaspersky’s investigation uncovered a diverse array of payloads. These included the Lumma and Vidar infostealers, the RenEngine loader, ransomware droppers, and various botnet loaders. The wide variety of tools suggests that multiple independent threat groups are leveraging this exploitation technique, rather than a single, coordinated actor. Key Kaspersky detection verdicts associated with this campaign include:
HEUR:Trojan-PSW.Win32.genHEUR:Backdoor.Win32.DarkKometTrojan-Dropper.Python.AgentHEUR:Trojan-Ransom.Win32.Gen.genPDM:Trojan.Win32.Generic
As noted, China accounts for 89% of the malicious download attempts, with the wallpaper art styles and titles explicitly tailored for Chinese-speaking users. Russia follows with 5.5% of the victim pool, while Singapore (1.4%), Hong Kong (0.9%), Germany (0.9%), Vietnam (0.9%), India (0.5%), and Canada (0.5%) also saw compromised users. Researchers caution that the campaign’s underlying template could easily be adapted to target any global audience.
What You Should Do
- Avoid downloading application-type wallpapers from unknown or unverified creators on the Steam Workshop.
- Scan all downloaded Workshop content with a reputable, up-to-date antivirus solution before applying it to your system.
- Enable Steam Guard and two-factor authentication (2FA) on your Steam account to significantly limit the impact of a potential session hijack.
- Regularly monitor your system processes for unexpected executables, such as
Synaptics.exe, or unsigned DLLs loading from directories likeProgramData.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.