惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

P
Proofpoint News Feed
云风的 BLOG
云风的 BLOG
Apple Machine Learning Research
Apple Machine Learning Research
Hugging Face - Blog
Hugging Face - Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Google DeepMind News
Google DeepMind News
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
雷峰网
雷峰网
B
Blog
月光博客
月光博客
博客园 - 【当耐特】
WordPress大学
WordPress大学
Microsoft Azure Blog
Microsoft Azure Blog
I
InfoQ
The GitHub Blog
The GitHub Blog
Engineering at Meta
Engineering at Meta
Jina AI
Jina AI
博客园 - Franky
MyScale Blog
MyScale Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Last Week in AI
Last Week in AI
B
Blog RSS Feed
H
Help Net Security

TechSpot

Flagship Rematch: Ryzen 7 5800X3D vs. Core i9-12900K Slack chats and internal data from failed startups are finding a second life in AI training A $5 Bluetooth tracker hidden in a postcard exposed a warship's movements Leakers claim PlayStation 6 could offer at least 3x the performance of the PS5 The Mac Mini is no longer a niche product, it's local AI infrastructure IPv6 traffic reaches parity with IPv4 for the first time, Google data shows Xbox expansion cards are now cheaper than SSDs, and PC users are repurposing them Blue Origin prepares to reuse New Glenn booster in bid to challenge SpaceX Nvidia could bring back the 12GB RTX 3060 as supply issues disrupt GPU roadmap What was the first OS you ever used? SNK revives NeoGeo AES with modern upgrades and HDMI support Valve's Proton 11 beta boosts Linux gaming with better performance and classic game support Researchers warn Microsoft Defender vulnerability is already being exploited A four-day Steam freebie turned into $250,000 for an indie game AMD may relaunch Ryzen 7 5800X3D for AM4's 10th anniversary This humanoid robot can almost run as fast as a human sprinter Two New Jersey men jailed for helping North Korean IT workers infiltrate 100+ companies A $7,000 DIY radar project is taking on hardware that usually costs over $100,000 Metro 2039 is going darker than ever, launching this winter on PC and consoles Gemini arrives on macOS with a dedicated desktop app AI infrastructure boom pushes AMD, Intel and Arm to new valuation heights New self-healing material can repair itself over 1,000 times, extend the lifespan of cars and aircraft Japan's bullet train to debut high-tech private cabins, for an added fee Memory card and flash drive pricing surges 120%, with some models spiking 260% Open-source tool decrypts all private data collected by Windows Recall on Copilot PCs The 2026 PC and Console Gaming Report shows most revenue now comes from games outside the Top 20 PureMac is a new open-source macOS cleanup and app removal tool Your Airbnb host might actually be AI Steam might soon display 30-day price history for game deals Intel brings 18A process to budget laptops with new Core Series 3 CPUs
Cybercriminals have been distributing malware via Steam f...
Kishalaya Kundu · 2026-06-19 · via TechSpot

Serving tech enthusiasts for over 25 years.
TechSpot means tech analysis and advice you can trust.

WTF?! According to Kaspersky, cybercriminals have been targeting Steam users with a sustained malware campaign since 2025, distributing malicious software disguised as desktop wallpapers. The attack hijacked the accounts of gamers using Steam's live wallpaper application Wallpaper Engine, which ranks among the platform's most popular non-game downloads.

The attack reportedly abused Wallpaper Engine's "Application Wallpaper" executable, which runs as a standalone Windows program and can include community-developed games, planners, calendars, system monitors, and other widgets. However, because the app allows unverified third-party code to run on users' systems, it can be abused by threat actors to target unsuspecting users.

The researchers found that the attackers used two primary methods to distribute malware. The first involved archives containing the executable wallpaper alongside a malicious payload, typically including compromised .exe files, DLLs, or scripts. The malware was also frequently concealed within password-protected archives and executed automatically when the wallpaper was applied.

Once applied, the infected executables stole users' account credentials, hijacked live sessions, and transmitted the stolen data to servers controlled by the attackers. The researchers discovered dozens of malicious application wallpapers on Steam Workshop, some of which were downloaded tens of thousands of times.

To test the attackers' modus operandi, the researchers launched a wallpaper containing a malicious game called NTRaholic, which ran "flawlessly." The gameplay and controls worked as advertised, raising no suspicion at first glance. However, unbeknownst to the user, the wallpaper dropped a backdoor called Synaptics.exe, part of the notorious DarkKomet malware family.

The executable that launched the game was named ._cache_GAME1.exe, but it also installed a system library called AggregatorHost.dll, which contained a malicious payload designed to steal user data and transmit it to the attackers' command-and-control server. Once the attackers gained control of the active session, they used the compromised account to upload additional malicious wallpapers to Steam Workshop.

The campaign primarily targeted gamers in China, who accounted for 89% of the compromised downloads. Users in Germany, Canada, Russia, Singapore, Hong Kong, Vietnam, and India were also affected, though in much smaller numbers. Steam has since removed all of the malicious wallpapers, but Kaspersky is still urging users to run antivirus scans before applying wallpapers that include built-in executables.