Gamers beware: malicious wallpapers on Steam found stealing accounts

This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).

Since late 2025, attackers have been distributing malware through Steam Workshop by embedding malicious code inside Wallpaper Engine's 'application wallpaper' packages. These wallpapers can silently install backdoors (DarkKomet), infostealers (Lumma, Vidar), crypto miners, and ransomware. One analyzed sample drops a backdoor and a modified system DLL that hunts for Steam credentials and exfiltrates them to attacker-controlled servers. Dozens of infected wallpapers were each downloaded thousands of times, with 89% of victims in China. Steam has removed the identified wallpapers, but new ones keep appearing. Indicators of compromise including MD5 hashes and C2 server addresses are provided.

6m read timeFrom securelist.com
Post cover image
Table of contents
Application wallpapers: a built-in security riskInside an infected game wallpaperHow to stay safeIndicators of compromise
269 Impressions