AUTO-UPDATED

Steam forum ClickFix attacks infect gamers with XMRig cryptominers

Threat actors are exploiting Steam discussion forums by posting malicious PowerShell commands disguised as technical fixes that secretly install XMRig cryptominers on victims' Windows computers.

Key Points

  • Attackers use fake Steam accounts to reply to user support threads with instructions to run PowerShell commands.
  • The malicious script masquerades as a "msf utility \ PC Opt" tool that performs fake system maintenance tasks.
  • Once executed with administrator privileges, the malware creates a hidden directory and adds a Microsoft Defender exclusion to avoid detection.
  • The script downloads and installs an XMRig miner, creating a scheduled task to ensure the malicious process persists after system reboots.
  • Users are advised to check for the 'C:\Windows\Background' directory and remove any scheduled tasks starting with 'XMRig-' if they suspect compromise.

Why it Matters

This campaign highlights the effectiveness of ClickFix social engineering, which bypasses automated security protections by tricking users into manually executing malicious code. Because the malware runs with system-level privileges, it poses a significant risk to device integrity and may necessitate a full operating system reinstallation to ensure complete removal.
BleepingComputer Published by Lawrence Abrams
Read original