Kaspersky Finds Malware in Steam Wallpaper Engine Hijacking Accounts

Kaspersky discovers a campaign where attackers hide malware in Steam Wallpaper Engine packages, targeting Chinese gamers with credential stealers and ransomware.

Kaspersky Finds Malware in Steam Wallpaper Engine Hijacking Accounts

Attackers have been smuggling malware into Steam through animated desktop wallpapers since late last year. The campaign specifically targets gamers in China by pushing credential stealers and crypto miners disguised as legitimate content.

Attackers smuggle malicious packages into the desktop background tool to steal credentials and spread malware across systems.

The threat centers on Valve's Wallpaper Engine, a popular tool for creating custom desktop backgrounds. Users who install malicious packages give attackers access to their systems and account credentials.

Wallpaper Engine includes an application wallpaper type that allows standalone executable programs to run in the background. Attackers exploit this feature by delivering malicious EXE files or DLLs alongside legitimate assets inside password-protected archives.

The malware uses tools like DarkKomet backdoor and tampered AggregatorHost.dll to locate Steam applications and steal credentials. Kaspersky reports that 89 percent of these malicious downloads targeted users in China, with payloads including credential stealers and ransomware.

Discussion

0 comments

Log in to join the thread with a thoughtful take, question, or correction.

Add to the discussion