Cybersecurity researchers at Kaspersky discovered that malicious actors are weaponizing Steam Workshop wallpapers to distribute backdoors, infostealers, and ransomware to thousands of unsuspecting gamers using Wallpaper Engine.
Key Points
- Kaspersky identified dozens of malicious application wallpapers on the Steam Workshop that have been active since late 2025.
- The malware payloads, including Lumma, Vidar, and various cryptominers, execute automatically upon the installation of the infected wallpaper files.
- Affected content was primarily distributed through password-protected archives or bundled packages within the Steam platform.
- Valve has removed the identified malicious uploads, though security experts warn that attackers can easily re-upload new infected content.
- The campaign has impacted a significant number of users, with the highest concentration of victims located in Russia and China.