Hackers Abuse Steam's Wallpaper Engine to Distribute Malware

Gamers Beware: Hackers Abuse Steam's Wallpaper Engine to Distribute Infostealers and Ransomware

MEDIUM
June 19, 2026
5m read
MalwarePhishingCyberattack

Impact Scope

People Affected

Thousands of users

Industries Affected

Media and Entertainment

Geographic Impact

ChinaRussiaGermanyCanadaIndiaVietnam (global)

Related Entities

Organizations

Products & Tech

SteamWallpaper Engine

Other

Full Report

Executive Summary

A recent investigation by Kaspersky has uncovered a widespread malware distribution campaign targeting gamers on the Steam platform. Threat actors are abusing the Steam Workshop and the popular 'Wallpaper Engine' application to deliver malware. They embed malicious payloads within user-submitted animated wallpapers, which, when downloaded and activated, infect the user's computer. The campaign has distributed a variety of malware, including infostealers, backdoors, and ransomware, with a primary focus on users in China and Russia. The technique is particularly deceptive as it uses a trusted platform (Steam) and a legitimate application feature to execute malicious code, often without any obvious signs of compromise.

Threat Overview

The attack vector is the 'application wallpaper' feature within Wallpaper Engine, a tool that allows users to have animated and interactive desktop backgrounds. This feature permits wallpapers to include and run executable files (.exe). Attackers exploit this by:

  1. Creating Malicious Wallpapers: They package malware alongside or within an otherwise functional animated wallpaper.
  2. Uploading to Steam Workshop: The malicious content is uploaded to the public Steam Workshop, a repository where users share custom game content and application assets.
  3. Deceptive Lure: The wallpapers are given enticing names and visuals. Some even include playable mini-games to mask their malicious nature.
  4. Execution: When a user subscribes to, downloads, and runs the malicious wallpaper, the embedded executable runs in the background, infecting their system.

This campaign is not attributed to a single actor, as researchers have observed a diverse range of malware being distributed through this method.

Technical Analysis

The core of this attack is the abuse of a legitimate application's functionality. Wallpaper Engine is not inherently malicious, but its design allows for the execution of code, which threat actors have turned into an infection vector. The malware payloads observed include:

  • Infostealers: Lumma and Vidar, which are designed to steal browser cookies, saved passwords, cryptocurrency wallets, and other sensitive information.
  • Backdoors: DarkKomet, a remote access trojan (RAT) that can give an attacker full control over the victim's machine, including the ability to hijack active Steam sessions to steal accounts.
  • Loaders: The RenEngine loader, used to download and execute additional malware payloads.
  • Other Malware: Cryptocurrency miners and ransomware have also been seen.

MITRE ATT&CK Techniques:

Impact Assessment

The primary targets are individual gamers, but the impact can be significant:

  • Account Theft: Compromise of Steam accounts, which can have significant monetary value, as well as other online accounts (email, social media).
  • Financial Loss: Theft of cryptocurrency wallet keys and banking credentials.
  • Identity Theft: Loss of sensitive personal information stored on the computer.
  • Further Infection: The infected machine can be used as part of a botnet for DDoS attacks or to spread the malware further to the victim's contacts. For prolific gamers or streamers, the loss of their Steam account can also represent a loss of community and income.

IOCs — Directly from Articles

No specific file hashes or C2 domains were mentioned in the source articles.

Cyber Observables — Hunting Hints

For individual users, hunting can be difficult. However, signs of infection could include:

  • Observable: Unexpected new processes running in Task Manager, especially after changing a wallpaper in Wallpaper Engine.
  • Observable: Increased CPU or GPU usage when idle, which could indicate a cryptocurrency miner.
  • Observable: Unexplained network activity from unknown applications, visible in tools like Resource Monitor.
  • Observable: Security alerts from antivirus software after installing a new wallpaper.

Detection & Response

  • Antivirus/Antimalware: Use a reputable antivirus solution and keep it updated. It may detect the malware payloads when they are written to disk or executed.
  • Process Monitoring: Be mindful of running processes. If a new, unknown process appears after running a wallpaper, terminate it and uninstall the wallpaper immediately.
  • Account Security: If you suspect a compromise, immediately change your Steam password and passwords for any other important accounts. Enable Steam Guard (MFA) on your Steam account.
  • D3FEND Techniques: For advanced users, employing endpoint security tools that use D3-PA: Process Analysis can help identify suspicious processes spawned by wallpaper32.exe or wallpaper64.exe.

Mitigation

  1. Source Vetting: Only download wallpapers from highly-rated, reputable creators on the Steam Workshop. Check the comments section for any warnings from other users.
  2. Avoid 'Application' Wallpapers: Be extremely cautious with wallpapers of the 'Application' type, as these are the ones that can run executables. Prefer 'Video' or 'Scene' type wallpapers.
  3. Enable MFA: Secure your Steam account with Steam Guard. This will prevent attackers from taking over your account even if they steal your password.
  4. Regular Scans: Run regular scans with your antivirus software.
  5. Principle of Least Privilege: Run your daily user account as a standard user, not an administrator. This can limit the damage a malware infection can cause.

Timeline of Events

1
June 16, 2026
Kaspersky publishes its report detailing the malware campaign.
2
June 18, 2026
Multiple news outlets report on the Kaspersky findings, and Valve begins removing malicious content.
3
June 19, 2026
This article was published

MITRE ATT&CK Mitigations

Educate users to be cautious about the source and type of content they download from public repositories like Steam Workshop.

Use a reputable antivirus solution to scan downloaded files and detect known malware payloads.

Enable MFA (Steam Guard) on Steam accounts to protect them from being taken over even if credentials are stolen.

While not directly applicable to Wallpaper Engine's design, using endpoint security that monitors for suspicious process chains can help prevent the malicious executables from running undetected.

D3FEND Defensive Countermeasures

Users and endpoint security solutions should closely monitor the process activity associated with Wallpaper Engine (wallpaper32.exe or wallpaper64.exe). A key detection strategy is to look for these legitimate processes spawning unexpected child processes, especially command shells (cmd.exe, powershell.exe) or any other executable that is not part of the core application. This is highly anomalous behavior for a wallpaper application. An EDR or advanced security tool can be configured to alert or block such process chains, effectively containing the malware before it can execute its primary payload. This behavioral approach is more robust than signature-based detection as it can catch novel malware distributed through this vector.

To mitigate the impact of account credential theft by infostealers like Lumma and Vidar, all Steam users must enable Steam Guard, Steam's native MFA solution. This requires a code from a mobile app or email for logins from new devices. Even if an attacker successfully infects a user's machine and steals their username and password, MFA will prevent them from logging into the Steam account and hijacking it. This is a critical defense-in-depth measure that protects the user's valuable digital assets and identity, rendering the credential theft aspect of the malware far less effective.

Timeline of Events

1
June 16, 2026

Kaspersky publishes its report detailing the malware campaign.

2
June 18, 2026

Multiple news outlets report on the Kaspersky findings, and Valve begins removing malicious content.

Article Author

Jason Gomes

Jason Gomes

• Cybersecurity Practitioner

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.

Threat Intelligence & AnalysisSecurity Orchestration (SOAR/XSOAR)Incident Response & Digital ForensicsSecurity Operations Center (SOC)SIEM & Security AnalyticsCyber Fusion & Threat SharingSecurity Automation & IntegrationManaged Detection & Response (MDR)

Tags

SteamWallpaper EngineMalwareKasperskyLummaVidarDarkKometGaming

📢 Share This Article

Help others stay informed about cybersecurity threats

🎯 MITRE ATT&CK Mapped

Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.

🧠 Enriched & Analyzed

Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.

🛡️ Actionable Guidance

Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.

🔗 STIX Visualizer

Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.

Sigma Generator

Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.