Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    GhostTree Attack Abused Recursive Windows Junctions to Hide Malware

    June 16, 2026

    Steam Workshop abused to spread malware via Wallpaper Engine app

    June 16, 2026

    Malicious JetBrains Marketplace plugins steal AI API keys from developers

    June 16, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»Steam Workshop abused to spread malware via Wallpaper Engine app
    News

    Steam Workshop abused to spread malware via Wallpaper Engine app

    adminBy adminJune 16, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Steam Workshop abused to spread malware via Wallpaper Engine app

    Threat actors are abusing Steam Workshop, Valve’s community hub for downloading game-related content, to push various malware hidden in wallpaper packages.

    Infected wallpapers can lead to hijacking Steam accounts, compromising the system with a backdoor, or running cryptomining processes.

    Steam Workshop is a built-in content-sharing platform on Valve’s Steam gaming service where users can upload and download community-created content for games and applications.

    image

    The content includes mods, maps, skins, save files, tools, and other user-generated content such as wallpapers.

    Malware in the wallpaper

    In a report today, researchers at cybersecurity company Kaspersky say that the attacks abuse the Wallpaper Engine desktop customization application available on Steam, which has nearly a million reviews.

    Wallpaper Engine supports four wallpaper types that render videos, interactive scenes, web pages that can play audio and video, and applications, which are active windows from software that Wallpaper Engine sets as the desktop background.

    Application wallpapers are executable Windows applications that can include games, desktop widgets, and system monitoring tools. Kaspersky warns that the feature represents a built-in security risk and has been abused to deliver malware to Steam users.

    According to the researchers, attackers took advantage of this security gap since at least late 2025, uploading malicious wallpaper files to the Steam Workshop and tricking users into installing them through Wallpaper Engine.

    “We discovered dozens of these malicious application wallpapers floating around Steam Workshop, and each one had already been downloaded thousands – or even tens of thousands – of times,” Kaspersky notes.

    Malicious wallpaper application
    Malicious wallpaper application
    Source: Kaspersky

    Analysis of compromised wallpapers revealed that the malware is bundled either directly in the package or inside password-protected archives that the user is tricked into opening.

    The payloads execute automatically the moment the user installs the wallpaper, the researchers say.

    Attack flow
    Observed attack flow
    Source: Kaspersky

    Kaspersky tested one of these wallpapers posing as a game called NTRaholic, which launched as expected upon execution to reduce suspicion. However, a backdoor file part of the DarkKomet malware family was installed in the background.

    A custom version of a system library called ‘AggregatorHost.dll’ was also installed to search for Steam accounts on the computer and steal account credentials.

    Stealing Steam data
    Stealing Steam data
    Source: Kaspersky

    The researchers found multiple cases involving other malware families, such as the Lumma and Vidar infostealers, cryptocurrency miners, botnet loaders, RanEngine, and even ransomware strains, showing that Wallpaper Engine was abused by multiple threat actors.

    While Steam has identified and removed all the malicious wallpaper applications that Kaspersky identified, but researchers are warning that threat actors are likely to submit new ones.

    Apart from downloading content from trusted sources, Kaspersky recommends users to scan anything fetched from Steam Workshop using an up-to-date antivirus product.


    article image

    Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

    The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

    Get the whitepaper



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleMalicious JetBrains Marketplace plugins steal AI API keys from developers
    Next Article GhostTree Attack Abused Recursive Windows Junctions to Hide Malware
    admin
    • Website

    Related Posts

    News

    GhostTree Attack Abused Recursive Windows Junctions to Hide Malware

    June 16, 2026
    News

    Malicious JetBrains Marketplace plugins steal AI API keys from developers

    June 16, 2026
    News

    Hackers Are Hijacking Entire Roblox Games Now

    June 16, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202677 Views

    IP Address Investigations and Local OSINT

    March 20, 202633 Views

    Defending Canada’s Digital Frontier: Combating Phishing, Social Engineering, Ransomware, and Malware

    March 23, 202632 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202677 Views

    IP Address Investigations and Local OSINT

    March 20, 202633 Views

    Defending Canada’s Digital Frontier: Combating Phishing, Social Engineering, Ransomware, and Malware

    March 23, 202632 Views
    Our Picks

    GhostTree Attack Abused Recursive Windows Junctions to Hide Malware

    June 16, 2026

    Steam Workshop abused to spread malware via Wallpaper Engine app

    June 16, 2026

    Malicious JetBrains Marketplace plugins steal AI API keys from developers

    June 16, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.