Steam Workshop exploited to spread sophisticated malware

NGUYỄN ĐĂNG |

Hackers take advantage of Steam Workshop to spread malware disguised as computer wallpapers, leading to the risk of the device being infected.

Kaspersky researchers discovered a malware distribution campaign being deployed, taking advantage of Steam Workshop and Wallpaper Engine - popular applications on Steam that allow users to create and share animated wallpapers for computers.

The research team identified many wallpaper packages infected with malware with thousands of downloads. The main targets of this campaign are Steam users in China and Russia, as well as victims in Singapore, Hong Kong (China), Germany, Vietnam, India and Canada. The attacker's goal is to steal game accounts and deploy other types of malware on victims' devices.

Steam Workshop is an integrated feature on the Steam platform, allowing users to easily search, install and manage content created by the community such as mods, custom maps, game objects and device wallpapers. Meanwhile, the Wallpaper Engine application supports many different wallpaper formats, including videos, interactive scenes, websites and applications.

The application-style wallpaper support feature allows programs to run directly on the user's Windows computer. This inadvertently creates loopholes for attackers to spread malware under the guise of fake legal content. Kaspersky has discovered dozens of wallpaper packages infected with malware posted on Steam Workshop. Many of these packages record thousands, even tens of thousands of downloads.

Tin tặc lợi dụng Steam Workshop để phát tán mã độc ngụy trang dưới dạng hình nền máy tính, dẫn đến nguy cơ thiết bị bị lây nhiễm mã độc và tài khoản người dùng bị đánh cắp. Ảnh: Nhi Lê
Hackers take advantage of Steam Workshop to spread malware disguised as computer wallpapers, leading to the risk of the device being infected with malware and user accounts being stolen. Photo: Nhi Le

Attackers mainly use two main methods of spreading malware. The first way is to directly embezzle malicious executable files, DLL libraries, and scripts into the wallpaper package. In other cases, the malware is hidden in a password-protected compressed file, in which the password is inserted into the file name or configuration file. After installing the wallpaper, the malware will be automatically activated and executed.

High-risk attacks are carried out by many different groups or individuals instead of just one group, and are not limited to a specific malware family. In many cases, Kaspersky has detected malicious wallpapers that spread information-stealing malware such as Lumma and Vidar, as well as RenEngine malware downloaders. Kaspersky's security solutions now have the ability to detect and prevent all types of malware related to this campaign.

Mr. Maxim Starodubov, a cybersecurity expert at Kaspersky, commented: "Even reliable platforms can be exploited to spread malware. These attacks are based on user trust in content stored on legitimate ecosystems. Although most of the malware used is known in advance, this spread mechanism still helps hackers access a large number of potential victims through seemingly harmless content.

To protect users, Kaspersky experts have given advice:

Be careful when downloading any application, even from sources that are considered reliable.

Check the credibility and authenticity of the developer or content creator before installing any content shared by the community.

Use reputable security solutions to detect and prevent threats.

NGUYỄN ĐĂNG
RELATED NEWS

Children under 16 years old on Roblox will be managed according to specific age groups

|

The Roblox platform expands online child protection measures, while increasing parental control over young user accounts.

After subscriber authentication, users should immediately check this content

|

After applying one-way SIM lock, many people have started to verify or authenticate subscriber information.

Hackers using password-stealing malware are increasing in Southeast Asia

|

Password-stealing malware (password stealer) is being increasingly exploited by bad actors to attack organizations in Southeast Asia.

Stone dust covers houses, people's lives are seriously affected

|

Quang Tri - Stone dust and noise from stone mining and transportation activities lasting for many years have affected hundreds of households in Truong Son commune.

Ho Chi Minh City will exempt bus tickets for people from July

|

Ho Chi Minh City is expected to spend about 665 billion VND to exempt 100% of bus ticket prices for all people from July 1 to the end of 2026.

Reasons why the Ministry of Home Affairs proposed that the Prime Minister decide on the entire holiday schedule

|

According to the Ministry of Home Affairs, the Prime Minister's proposal to decide on the entire holiday schedule will help proactively arrange holidays and notify people and businesses early.

Israel negotiates with the US on the continued deployment of troops in Lebanon

|

Exchanges between the US and Israel took place after the US and Iran signed a temporary agreement related to Lebanon's sovereignty.

Oil prices decrease by 2,343 VND/liter from 3 pm today

|

In the price adjustment period on June 18, 2026, domestic gasoline and oil prices simultaneously decreased.

Children under 16 years old on Roblox will be managed according to specific age groups

Cát Tiên |

The Roblox platform expands online child protection measures, while increasing parental control over young user accounts.

After subscriber authentication, users should immediately check this content

HẠO THIÊN |

After applying one-way SIM lock, many people have started to verify or authenticate subscriber information.

Hackers using password-stealing malware are increasing in Southeast Asia

NGUYỄN ĐĂNG |

Password-stealing malware (password stealer) is being increasingly exploited by bad actors to attack organizations in Southeast Asia.