Threat actors are exploiting Steam discussion forums by posting malicious PowerShell commands disguised as technical fixes that secretly install XMRig cryptominers on victims' Windows computers.
Key Points
- Attackers use fake Steam accounts to reply to user support threads with instructions to run PowerShell commands.
- The malicious script masquerades as a "msf utility \ PC Opt" tool that performs fake system maintenance tasks.
- Once executed with administrator privileges, the malware creates a hidden directory and adds a Microsoft Defender exclusion to avoid detection.
- The script downloads and installs an XMRig miner, creating a scheduled task to ensure the malicious process persists after system reboots.
- Users are advised to check for the 'C:\Windows\Background' directory and remove any scheduled tasks starting with 'XMRig-' if they suspect compromise.