Steam forum ClickFix attacks infect gamers with XMRig cryptominers
Steam discussion forums are being exploited in ClickFix social engineering attacks where threat actors post fake fixes for game or computer issues. Victims are tricked into running PowerShell commands that download and install the XMRig cryptominer on their devices. The malicious script masquerades as a Windows optimization utility but disables security features, installs the miner with SYSTEM privileges, and persists via scheduled tasks and Microsoft Defender exclusions. Users executing these commands risk unauthorized cryptocurrency mining on their systems.
AI Analysis
Technical Summary
Threat actors abuse Steam forums by posting replies with PowerShell commands claiming to fix common gaming or system problems. When executed by victims, these commands download and install the XMRig cryptominer. The PowerShell script pretends to be a Windows optimization tool, displaying fake progress messages while disabling TLS certificate validation and Microsoft Defender scanning for the installation directory. It creates a scheduled task to run the miner with SYSTEM privileges at startup and modifies firewall rules to allow outbound connections to the attacker's server. This ClickFix attack relies on social engineering to bypass security controls by requiring manual victim interaction.
Potential Impact
Successful execution results in the victim's device being infected with the XMRig cryptominer, which uses system resources for unauthorized cryptocurrency mining. The malware runs with SYSTEM privileges, evades Microsoft Defender detection by adding exclusions, and persists via scheduled tasks. This can degrade system performance and increase power consumption. There is no indication from the data that additional payloads or further compromise beyond cryptomining have been confirmed.
Mitigation Recommendations
No official patch or vendor fix is applicable as this is a social engineering attack vector. Users should never run PowerShell commands from untrusted sources, especially in forums. To remediate infections, check for the presence of the 'C:\Windows\Background' directory, Microsoft Defender exclusions for that path, and scheduled tasks named 'XMRig-[computer name]'. Run a full antivirus scan to detect and remove the miner. If the miner is not detected by antivirus, manually remove the scheduled task, delete the Defender exclusion, and remove the installation directory. Reinstalling the operating system may be necessary to ensure complete removal and to mitigate any unknown additional malicious activity.
Steam forum ClickFix attacks infect gamers with XMRig cryptominers
Description
Steam discussion forums are being exploited in ClickFix social engineering attacks where threat actors post fake fixes for game or computer issues. Victims are tricked into running PowerShell commands that download and install the XMRig cryptominer on their devices. The malicious script masquerades as a Windows optimization utility but disables security features, installs the miner with SYSTEM privileges, and persists via scheduled tasks and Microsoft Defender exclusions. Users executing these commands risk unauthorized cryptocurrency mining on their systems.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Threat actors abuse Steam forums by posting replies with PowerShell commands claiming to fix common gaming or system problems. When executed by victims, these commands download and install the XMRig cryptominer. The PowerShell script pretends to be a Windows optimization tool, displaying fake progress messages while disabling TLS certificate validation and Microsoft Defender scanning for the installation directory. It creates a scheduled task to run the miner with SYSTEM privileges at startup and modifies firewall rules to allow outbound connections to the attacker's server. This ClickFix attack relies on social engineering to bypass security controls by requiring manual victim interaction.
Potential Impact
Successful execution results in the victim's device being infected with the XMRig cryptominer, which uses system resources for unauthorized cryptocurrency mining. The malware runs with SYSTEM privileges, evades Microsoft Defender detection by adding exclusions, and persists via scheduled tasks. This can degrade system performance and increase power consumption. There is no indication from the data that additional payloads or further compromise beyond cryptomining have been confirmed.
Mitigation Recommendations
No official patch or vendor fix is applicable as this is a social engineering attack vector. Users should never run PowerShell commands from untrusted sources, especially in forums. To remediate infections, check for the presence of the 'C:\Windows\Background' directory, Microsoft Defender exclusions for that path, and scheduled tasks named 'XMRig-[computer name]'. Run a full antivirus scan to detect and remove the miner. If the miner is not detected by antivirus, manually remove the scheduled task, delete the Defender exclusion, and remove the installation directory. Reinstalling the operating system may be necessary to ensure complete removal and to mitigate any unknown additional malicious activity.
Technical Details
- Article Source
- {"url":"https://www.bleepingcomputer.com/news/security/steam-forum-clickfix-attacks-infect-gamers-with-xmrig-cryptominers/","fetched":true,"fetchedAt":"2026-07-25T23:37:06.798Z","wordCount":991}
Threat ID: 6a6548a29c2644c7f8142c98
Added to database: 07/25/2026, 23:37:06 UTC
Last enriched: 07/25/2026, 23:37:13 UTC
Last updated: 07/26/2026, 00:53:45 UTC
Views: 17
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.