How hackers used Steam Workshop to spread malware

26 views

Steam Workshop has become the latest surprising malware delivery channel, with attackers hiding malicious code inside Wallpaper Engine “application wallpapers” to steal Steam credentials, install…

Benjamin LloydJul 22, 20264 min read

Steam Workshop has become the latest surprising malware delivery channel, with attackers hiding malicious code inside Wallpaper Engine “application wallpapers” to steal Steam credentials, install backdoors, and run crypto miners. The attack is effective because the files looked like ordinary community content. But they could execute like Windows apps once installed.

Steam Workshop helps make gaming more social and customizable, but attackers exploit that trust by disguising malware as user-generated content. Let’s take a look at how the scam worked, the types of malware researchers discovered during the campaign. And what you can do to stay safe as similar threats continue to emerge.

Key takeaways

  • Hackers abused the Steam Wallpaper Engine application wallpaper feature, which can run executable Windows applications as desktop backgrounds.
  • Attackers sometimes bundled the malicious files directly with the wallpaper and sometimes hid them inside password-protected archives.
  • Researchers found backdoors, infostealers, cryptocurrency miners, botnet loaders, and even ransomware in the campaign.
  • Valve removed the identified malicious uploads, but the method remains a risk because attackers can repost new files.

How the scam worked

The campaign relied on a simple social engineering trick. Make malicious files look like normal wallpaper content and let users install them through Steam Workshop. The scam centered on Wallpaper Engine, which supports several wallpaper formats. Including “application” wallpapers that are actually executable Windows apps rather than passive images.

That distinction matters because once a user installs an application wallpaper, any code included in the bundle can run on their machine automatically. Attackers either bundled malware directly into the wallpaper package or hid it inside a password-protected archive, encouraging users to open it and execute the malicious code.

Some samples even behaved normally at first to avoid suspicion, while a malicious payload ran in the background. In one example, a wallpaper posing as a game launched as expected but secretly installed a DarkKomet backdoor and a modified DLL designed to find Steam accounts and steal the user’s credentials.

What kind of malware was involved?

The infected payloads were not limited to one family of malware. Researchers reported DarkKomet backdoors, Lumma and Vidar infostealers, cryptocurrency miners, botnet loaders, RanEngine, and ransomware strains. This suggests that multiple criminal gangs have been using Steam Workshop to spread infections.

Attackers use infostealers to steal login details, session tokens and browser data. While backdoors give them remote access to infected devices and cryptominers quietly consume system resources for profit. The account-theft risk is particularly important for gamers because attackers can use stolen Steam credentials to hijack inventories, scam friends, and upload more malicious content from trusted accounts.

Researchers believe that thousands or even tens of thousands of users had already downloaded the malicious wallpapers before Steam removed them.

Why gamers are still exposed

The threat of downloading and installing infected wallpapers persists because the underlying trust model has not changed. Steam Workshop still encourages users to download community-made content. And attackers can keep creating new uploads that look legitimate.

Wallpaper Engine also remains a large, active ecosystem, giving malicious content a built-in audience. Even after Steam removes known samples, attackers can reuse the same tactic with a different filename, a fresh account, or a slightly altered payload to bypass the platform’s safeguards.

How to stay safe

Gamers should treat Workshop content like any other file from the internet, even when it appears on a trusted platform. The safest approach is to download only from creators you know, avoid application wallpapers unless you fully trust the source, and be cautious with archives or prompts that ask for extra steps to extract content.

It also helps to keep antivirus protection turned on and updated so downloaded files are scanned before they run. Steam account security matters too, so enable two-factor authentication, use a unique password, and watch for unexpected login alerts or inventory activity.

A good rule of thumb is that anything promising “free” customization, especially if it behaves like software rather than a static asset, should be thoroughly scanned. If a wallpaper or mod asks for unusual permissions, launches an installer. Or contains an archive inside an archive, stop before opening it.

Stay safe, stay aware

Steam Workshop malware worked because it blended in with content gamers already expect to trust, but the danger was real. Backdoors, infostealers, miners, botnet loaders, and ransomware all showed up in the same campaign. The best defense is to combine caution with layered protection, including antimalware, especially when downloading application-style wallpapers and other executable content. Pay attention to what you are downloading and you will immediately be better protected against scams.