Steam Workshop abused to spread malware via Wallpaper Engine app
Threat actors are abusing Steam Workshop, Valve's community hub for downloading game-related content, to push various malware hidden in wallpaper packages. [...]
AI Analysis
Technical Summary
Researchers at Kaspersky have identified that threat actors are exploiting the Wallpaper Engine application on Steam by uploading malicious wallpaper packages to the Steam Workshop. Wallpaper Engine supports application wallpapers that are executable Windows applications set as desktop backgrounds. Attackers embed malware payloads directly or within password-protected archives that execute automatically upon wallpaper installation. Malware families observed include DarkKomet backdoors, Lumma and Vidar infostealers, cryptocurrency miners, botnet loaders, RanEngine, and ransomware. The malicious wallpapers have been downloaded thousands of times before detection. Valve has removed known malicious wallpapers but the risk persists due to the platform's design and ongoing submissions.
Potential Impact
Successful installation of malicious wallpapers can lead to system compromise through backdoors, theft of Steam account credentials, unauthorized cryptocurrency mining, botnet participation, and ransomware infection. This impacts user privacy, system integrity, and potentially financial assets linked to Steam accounts or cryptocurrency wallets. The threat exploits a legitimate feature of Wallpaper Engine, increasing the risk of user deception and widespread infection.
Mitigation Recommendations
Valve has removed the known malicious wallpapers identified by researchers. Users should only download wallpapers from trusted sources on Steam Workshop and scan all downloaded content with up-to-date antivirus software before installation. There is no official patch for Wallpaper Engine's application wallpaper feature; users should exercise caution and consider disabling or avoiding application-type wallpapers. Monitor vendor advisories for updates on remediation or additional protective measures.
Steam Workshop abused to spread malware via Wallpaper Engine app
Description
Threat actors are abusing Steam Workshop, Valve's community hub for downloading game-related content, to push various malware hidden in wallpaper packages. [...]
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Researchers at Kaspersky have identified that threat actors are exploiting the Wallpaper Engine application on Steam by uploading malicious wallpaper packages to the Steam Workshop. Wallpaper Engine supports application wallpapers that are executable Windows applications set as desktop backgrounds. Attackers embed malware payloads directly or within password-protected archives that execute automatically upon wallpaper installation. Malware families observed include DarkKomet backdoors, Lumma and Vidar infostealers, cryptocurrency miners, botnet loaders, RanEngine, and ransomware. The malicious wallpapers have been downloaded thousands of times before detection. Valve has removed known malicious wallpapers but the risk persists due to the platform's design and ongoing submissions.
Potential Impact
Successful installation of malicious wallpapers can lead to system compromise through backdoors, theft of Steam account credentials, unauthorized cryptocurrency mining, botnet participation, and ransomware infection. This impacts user privacy, system integrity, and potentially financial assets linked to Steam accounts or cryptocurrency wallets. The threat exploits a legitimate feature of Wallpaper Engine, increasing the risk of user deception and widespread infection.
Mitigation Recommendations
Valve has removed the known malicious wallpapers identified by researchers. Users should only download wallpapers from trusted sources on Steam Workshop and scan all downloaded content with up-to-date antivirus software before installation. There is no official patch for Wallpaper Engine's application wallpaper feature; users should exercise caution and consider disabling or avoiding application-type wallpapers. Monitor vendor advisories for updates on remediation or additional protective measures.
Technical Details
- Article Source
- {"url":"https://www.bleepingcomputer.com/news/security/steam-workshop-abused-to-spread-malware-via-wallpaper-engine-app/","fetched":true,"fetchedAt":"2026-06-16T18:30:24.049Z","wordCount":763}
Threat ID: 6a3196400b89be68880898c1
Added to database: 06/16/2026, 18:30:24 UTC
Last enriched: 06/16/2026, 18:30:30 UTC
Last updated: 08/01/2026, 05:15:30 UTC
Views: 959
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.