惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
酷 壳 – CoolShell
酷 壳 – CoolShell
博客园 - 司徒正美
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Last Week in AI
Last Week in AI
大猫的无限游戏
大猫的无限游戏
博客园 - Franky
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
爱范儿
爱范儿
The Cloudflare Blog
阮一峰的网络日志
阮一峰的网络日志
博客园 - 叶小钗
博客园_首页
有赞技术团队
有赞技术团队
WordPress大学
WordPress大学
宝玉的分享
宝玉的分享
V
V2EX
V
Visual Studio Blog
博客园 - 三生石上(FineUI控件)
S
SegmentFault 最新的问题
量子位
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Apple Machine Learning Research
Apple Machine Learning Research
美团技术团队

Cyber Security News

AIRecon: AI-Powered Penetration Testing Tool with Kali Linux Sandbox Critical Chrome Vulnerabilities Allow Attackers to Execute Arbitrary Code - Update Now! UNC3753 Uses Screen-Sharing Sessions and RMM Tools to Exfiltrate Sensitive Legal Data New OnionDrop Loader Campaign Uses gainmsg C2 to Deliver LegionLoader Payloads ClickFix Campaign Uses EtherHiding and GULoader to Infect Windows Users via Fake CAPTCHA Ghostwriter Hackers Abuse Gmail Admin-Themed Emails to Steal Credentials and 2FA Codes The Half-Life of Threat Intelligence: When Does an IOC Stop Being Useful? Critical Fortinet FortiSandbox Vulnerabilities Actively Exploited in Attacks Aembit Extends IAM for Agentic AI to Microsoft Copilot Studio India Temporarily Bans Telegram Messenger Over Medical Exam Fraud Microsoft 365 Device Code Phishing Campaign Bypasses Password Theft With Legitimate Login Flow AppViewX Launches Agent Identity Security to Govern Agents for the AI and Quantum Era Hackers Weaponize Microsoft Teams Relay to Hide Ransomware Traffic Developer laptops are the credential store attackers are picking through in 2026, GitGuardian announces Endpoint Protection Interlock and Rhysida Ransomware Operations Share Supper Backdoor and Malware Codebase Novo Nordisk Confirms Cyber Attack — Hackers Accessed Patient Medical Data and Internal AI Assets Russian and Chinese Influence Actors Use AI to Evade Bot Detection and Mimic Human Behavior Microsoft Teams Analyze the Wi-Fi Hotspot Data Connected to an Employee’s Device PRC-Nexus Hackers Exploit REDCap Servers to Spy on US Medical Research Institutions Infinite Campus Data Breach Exposes 137,000 Users Personal Details OptinMonster Plugin Hack Exposes 1.2 Million Wordpress Sites to Cyberattack Ransomware Ecosystem Consolidates Around LockBit Alumni, Qilin, Hyflock, and The Gentlemen Hackers Abuse Legitimate RMM Tools in The Quarry IRS and SSA Phishing Campaigns LiteSpeed cPanel Plugin 0-Day Vulnerability Actively Exploited in the Wild Cisco SD-WAN vManage Vulnerability Exploited in Zero-Day Attacks Nearly 14,000 SimpleHelp Servers Exposed Amid Critical Authentication Bypass Disclosure Microsoft Site Showing Warning Following Certificate Expiry DPAPISnoop Tool Extracts CREDHIST Hashes for Offline Windows Credential Recovery SHADOWBYT3$ Allegedly Claim Breach of Nintendo, Stealing Sensitive Data Anthropic Updated Privacy Policy to Include Identity Verification for Claude Users
Hackers Abuse Steam Workshop Application Wallpapers to Hi...
Guru Baran · 2026-06-17 · via Cyber Security News

Threat actors have been abusing Valve’s Steam Workshop since late 2025, embedding malware inside Wallpaper Engine application wallpapers to hijack active Steam sessions and infect victims with backdoors, infostealers, and crypto miners, with 89% of targets located in China, according to a new Kaspersky report.

Wallpaper Engine is a hugely popular Steam application that lets users set animated, interactive wallpapers on their Windows desktops. With nearly one million reviews and approximately 100,000 daily active users, it presents an enormous attack surface.

The app supports several wallpaper types, videos, scenes, web pages, and application wallpapers, and that last category is what attackers zeroed in on. Application wallpapers are essentially standalone executables that run as the user’s desktop background, meaning launching one is no different from running an arbitrary program on your system.

Since anyone can publish content to Steam Workshop for free, attackers simply uploaded weaponized wallpapers disguised as games, widgets, and desktop tools. Kaspersky researchers discovered dozens of such malicious wallpapers, each already downloaded thousands — or even tens of thousands of times before detection.

Hackers Abuse Steam Workshop

Attackers used two primary distribution methods. In the first, the wallpaper archive bundled malicious executables, DLLs, or scripts alongside the visible application.

In the second, malware was concealed inside a password-protected archive; either the victim was tricked into entering the password manually, or a script extracted it automatically from the archive’s filename or a bundled JSON configuration file.

Once a victim launches the infected wallpaper, the attack executes silently and immediately. The wallpaper drops Synaptics.exe, a backdoor belonging to the DarkKomet remote access trojan family, into C:\ProgramData\Synaptics\.

Attack Flow (Source: Kaspersky)

Simultaneously, a secondary executable named ._cache_GAME1.exe launches to load the visible game (NTRaholic) — maintaining the illusion of a legitimate wallpaper while installing a patched version of AggregatorHost.dll loaded with a malicious payload.

This tampered system library then hunts for the Steam client on the host machine and hijacks the user’s active session. Stolen session data is subsequently exfiltrated to an attacker-controlled command-and-control server at hxxp://120.48.156[.]17/ey.php.

With a live session captured, the attackers gain full account access and can upload additional malicious wallpapers directly to Steam Workshop, perpetuating the infection cycle.

Beyond DarkKomet, Kaspersky’s investigation identified a wide range of payloads including Lumma and Vidar infostealers, the RenEngine loader, ransomware droppers, and botnet loaders.

The diversity of tools suggests multiple independent threat groups are leveraging the same technique rather than a single coordinated actor. Key Kaspersky detection verdicts include:

  • HEUR:Trojan-PSW.Win32.gen
  • HEUR:Backdoor.Win32.DarkKomet
  • Trojan-Dropper.Python.Agent
  • HEUR:Trojan-Ransom.Win32.Gen.gen
  • PDM:Trojan.Win32.Generic

China accounts for 89% of malicious download attempts, with wallpaper art styles and titles explicitly tailored to Chinese-speaking users. Russia follows at 5.5%, with Singapore (1.4%), Hong Kong (0.9%), Germany (0.9%), Vietnam (0.9%), India (0.5%), and Canada (0.5%) rounding out the victim pool. Researchers warn the campaign’s template could easily be redirected at any global audience.

Mitigation

Valve has removed all identified malicious wallpapers following Kaspersky’s disclosure, but researchers stress that new uploads continue to appear. Users should:

  • Avoid application-type wallpapers from unknown or unverified creators on Steam Workshop
  • Scan all downloaded Workshop content with an up-to-date antivirus before applying
  • Enable Steam Guard and two-factor authentication to limit session hijack impact
  • Monitor system processes for unexpected executables like Synaptics.exe or unsigned DLLs loading from ProgramData

Since Steam Workshop lacks per-upload code review, the platform’s trust model remains exploitable — and the burden of verification falls squarely on the end user.

CISO & Security Leaders: Your next breach may not have a face. Join ISC2’s LIVE webinar, “Ghost in the Machine”

Guru Baran

Guru Baranhttps://cybersecuritynews.com

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.