Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Steam forum ClickFix attacks infect gamers with XMRig cryptominers

0
Medium
Vulnerability
Published: 07/25/2026 (07/25/2026, 22:37:47 UTC)
Source: Bleeping Computer

Description

Steam discussion forums are being exploited in ClickFix social engineering attacks where threat actors post fake fixes for game or computer issues. Victims are tricked into running PowerShell commands that download and install the XMRig cryptominer on their devices. The malicious script masquerades as a Windows optimization utility but disables security features, installs the miner with SYSTEM privileges, and persists via scheduled tasks and Microsoft Defender exclusions. Users executing these commands risk unauthorized cryptocurrency mining on their systems.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/25/2026, 23:37:13 UTC

Technical Analysis

Threat actors abuse Steam forums by posting replies with PowerShell commands claiming to fix common gaming or system problems. When executed by victims, these commands download and install the XMRig cryptominer. The PowerShell script pretends to be a Windows optimization tool, displaying fake progress messages while disabling TLS certificate validation and Microsoft Defender scanning for the installation directory. It creates a scheduled task to run the miner with SYSTEM privileges at startup and modifies firewall rules to allow outbound connections to the attacker's server. This ClickFix attack relies on social engineering to bypass security controls by requiring manual victim interaction.

Potential Impact

Successful execution results in the victim's device being infected with the XMRig cryptominer, which uses system resources for unauthorized cryptocurrency mining. The malware runs with SYSTEM privileges, evades Microsoft Defender detection by adding exclusions, and persists via scheduled tasks. This can degrade system performance and increase power consumption. There is no indication from the data that additional payloads or further compromise beyond cryptomining have been confirmed.

Mitigation Recommendations

No official patch or vendor fix is applicable as this is a social engineering attack vector. Users should never run PowerShell commands from untrusted sources, especially in forums. To remediate infections, check for the presence of the 'C:\Windows\Background' directory, Microsoft Defender exclusions for that path, and scheduled tasks named 'XMRig-[computer name]'. Run a full antivirus scan to detect and remove the miner. If the miner is not detected by antivirus, manually remove the scheduled task, delete the Defender exclusion, and remove the installation directory. Reinstalling the operating system may be necessary to ensure complete removal and to mitigate any unknown additional malicious activity.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Article Source
{"url":"https://www.bleepingcomputer.com/news/security/steam-forum-clickfix-attacks-infect-gamers-with-xmrig-cryptominers/","fetched":true,"fetchedAt":"2026-07-25T23:37:06.798Z","wordCount":991}

Threat ID: 6a6548a29c2644c7f8142c98

Added to database: 07/25/2026, 23:37:06 UTC

Last enriched: 07/25/2026, 23:37:13 UTC

Last updated: 07/26/2026, 00:53:45 UTC

Views: 17

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses