Friday, 21 August 2026
Nigeria Communications Week
E-Business

Kaspersky Discovered a Malware Campaign Targeting Steam Users Through Infected Wallpaper

Chike Onwuegbuchi22 Jun 20260 Comments
Kaspersky Discovered a Malware Campaign Targeting Steam Users Through Infected Wallpaper
Kindly share this post

Kaspersky researchers have uncovered an ongoing malware distribution campaign leveraging Steam Workshop and Wallpaper Engine, a popular Steam application used to create and share animated desktop…

Kaspersky researchers have uncovered an ongoing malware distribution campaign leveraging Steam Workshop and Wallpaper Engine, a popular Steam application used to create and share animated desktop wallpapers.

Researchers identified multiple infected wallpaper packages which had accumulated thousands of downloads. Steam users in China and Russia were primarily targeted, with other victims located in Singapore, Hong Kong, Germany, Vietnam, India and Canada.

The main goal of the attackers was stealing gaming accounts and deploying additional malware.

Steam Workshop is a built-in feature of the Steam gaming platform that allows users to easily find, install, and manage user-generated content like mods, custom maps, game items, and wallpapers. The Wallpaper Engine app supports several wallpaper formats, including videos, interactive scenes, web pages, and applications.

The application-based wallpaper feature allows executable programs to run directly on a user's Windows computer, allowing attackers to distribute malicious software under the guise of legitimate content.

Kaspersky identified dozens of infected wallpaper packages available through Steam Workshop. Many of these packages had thousands or even tens of thousands of downloads.

There were two primary delivery methods that attackers used. In some cases, malicious executable files, DLLs, and scripts were bundled directly with the wallpaper package.

In others, attackers hid malware inside password-protected archives, with passwords embedded in archive names or configuration files. Once the wallpaper was installed, malicious payloads executed automatically.

For example, one of the malicious wallpaper samples discovered in December 2025 appeared to function legitimately at first, launching an embedded desktop game without any visible signs of compromise.

In the background, however, the wallpaper deployed the DarkKomet backdoor and installed a modified library designed to target Steam users: it harvested account information and hijacked active Steam sessions.

The attacks were likely conducted by multiple independent threat actors rather than a single group, and were not limited to a single malware family. Across multiple cases, Kaspersky detected malicious wallpapers distributing Lumma and Vidar infostealers and the RenEngine loader. Kaspersky's security solutions detect and block all malware associated with this campaign.

"Trusted platforms can be abused to distribute malware: the attacks rely on users trusting content hosted within legitimate ecosystems. While many of the malware families involved are well-known, the delivery mechanism enables attackers to reach large numbers of potential victims through seemingly harmless content," commented Maxim Starodubov, a cybersecurity expert at Kaspersky.

C
Published by

Chike Onwuegbuchi

Trained and practicing journalist passionate about telecommunications, fintech, cybersecurity, and digital economy reporting.

More in E-Business
E-Business

The Biggest Cost of Nigeria’s Crypto Stamp Duty Not 1.5%, But What Happens Next

By Chike Onwuegbuchi17 Aug 2026

There is a strange thing about regulation: everybody wants clarity until clarity comes with a bill. Given that is probably why the conversation around Nigeria’s proposed 1.5% stamp duty on virtual asset transactions has quickly become a debate about the number. Is 1.5% too much? Will it make crypto more expensive? Will users simply move elsewhere?