Malicious Steam Wallpapers Spread Malware to Gamers
ID: 7a0eaa87-176c-506b-a27f-ad5dc9dcb4a1
STIX ID: report--7a0eaa87-176c-506b-a27f-ad5dc9dcb4a1
Feed Name: securityonline.info
Attackers are embedding malware inside application-type wallpapers on the Steam Workshop (via Wallpaper Engine) to deliver backdoors (DarkKomet), infostealers, cryptominers and ransomware. A modified AggregatorHost.dll harvests Steam credentials and active sessions, exfiltrates them to command-and-control servers, and allows attackers to propagate malicious wallpapers from victim accounts; the campaign has recorded thousands of downloads and primarily targets gamers in China and Russia. Users are advised to avoid standalone executable wallpapers, enable multi-factor authentication, and keep antivirus updated.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
