🚨 Thousands of malicious wallpaper downloads detected impacting Steam users. 💻 Attackers used animated wallpapers to steal credentials and crypto data, targeting🚨 Thousands of malicious wallpaper downloads detected impacting Steam users. 💻 Attackers used animated wallpapers to steal credentials and crypto data, targeting

Thousands of malicious downloads in Steam wallpaper files discovered! What do crypto investors need to watch out for?

2026/06/20 01:49
3 min read
For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

Cybersecurity firm Kaspersky has uncovered malicious software embedded in certain Wallpaper Engine content distributed via the Steam Workshop. According to a report released by the company on Monday, attackers are disguising files—many appearing as animated desktop wallpapers—to steal Steam account credentials, hijack active sessions, and install additional malware on users’ systems.

Malicious content spread through Steam Workshop

The report details that these harmful files are often disguised as animated wallpapers featuring female anime characters. Kaspersky notes that Wallpaper Engine’s application-based feature for desktop wallpapers on Windows allows executable programs to run directly, which creates an opportunity for attackers to distribute malware under the guise of legitimate content.

According to the firm, while some wallpapers contain malware directly, others hide it within password-protected archives, which are extracted after installation. In one case detected in 2025, a wallpaper masqueraded as a launcher for a legitimate desktop game, but secretly installed the backdoor known as DarkKomet.

Account credentials and crypto wallets in the crosshairs

The investigation found that along with prominent infostealer malware families like Lumma and Vidar, attackers also leveraged the RenEngine loader. These programs are typically used to harvest usernames, passwords, browser data, and even cryptocurrency wallet credentials. Kaspersky researchers believe that more than one threat actor is likely behind the campaign, rather than a single group.

Mini glossary: An infostealer is a type of malware designed to collect sensitive information like login credentials, browser records, and digital wallet data from a computer. Lumma and Vidar are two of the most commonly known malware families in this domain.

Data from Kaspersky indicates that most victims are located in China and Russia, though infections have also been recorded in Singapore, Hong Kong, Germany, Vietnam, India, and Canada.

Surge in cases linked to Steam

Kaspersky researcher Maxim Starodubov attributes the effectiveness of these attacks to users’ trust in content hosted on reputable platforms. While many of the malware families used are not new, Starodubov explains that the attackers’ method of delivering them through seemingly harmless content enables wider reach among users.

The findings suggest a growing trend of similar incidents linked to Steam. In July 2025, cybersecurity company Prodaft reported that the game Chemia, under Steam Early Access, was misused to spread Hijack Loader, Fickle Stealer, and Vidar Stealer. Earlier in March, the FBI had announced an investigation into malware campaigns propagated via games such as Chemia, PirateFi, BlockBlasters, Dashverse, DashFPS, Lampy, Lunara, and Tokenova on Steam.

Additionally, a separate study highlighted in the same source draws attention to sophisticated, AI-powered computer worms capable of autonomously spreading across networks. Researchers from the University of Toronto, the Vector Institute, Cambridge University, and ServiceNow described a conceptual AI worm that can identify vulnerabilities, adapt its attack strategy, and replicate itself across systems.

The post Thousands of malicious downloads in Steam wallpaper files discovered! What do crypto investors need to watch out for? appeared first on COINTURK NEWS.

World Cup Combo: Aim for 200x

World Cup Combo: Aim for 200xWorld Cup Combo: Aim for 200x

Combine up to 20 World Cup matches in one order

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

Score Your Share of 50K USDT

Score Your Share of 50K USDTScore Your Share of 50K USDT

Complete DEX+ tasks to unlock the Champion Wheel