AUTO-UPDATED

The Steam Workshop Is Being Used To Spread Malware To Thousands Of Users

Cybersecurity firm Kaspersky has identified malicious actors distributing malware through the Steam Workshop, specifically targeting users of the Wallpaper Engine application to hijack personal Steam account credentials.

Key Points

  • Hackers are embedding malicious scripts and executables into popular animated wallpapers within the Steam Workshop platform.
  • Kaspersky reports that 89% of identified victims are located in China, with the malware specifically tailored to appeal to that demographic.
  • Once installed, the malware functions as a backdoor, stealing Steam credentials, credit card information, and potentially deploying ransomware or crypto-mining software.
  • The malicious files utilize known threats, including the DarkKomet backdoor and the Lumma and Vidar infostealers.
  • Users are advised to scan their systems for specific heuristic detections and immediately reset passwords and enable two-factor authentication if compromised.

Why it Matters

This incident highlights the significant security risks inherent in community-driven content platforms where user-uploaded files can bypass standard vetting processes. It serves as a critical reminder for gamers to exercise caution when downloading mods and to maintain updated antivirus software to protect sensitive personal and financial data.
BGR Published by staff@bgr.com (Aaron Greenbaum)
Read original