Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Steam Workshop abused to spread malware via Wallpaper Engine app

0
Medium
Malware
Published: Tue Jun 16 2026 (06/16/2026, 18:27:55 UTC)
Source: Bleeping Computer

Description

Threat actors are abusing the Steam Workshop platform to distribute malware hidden within wallpaper packages for the Wallpaper Engine application. These malicious wallpapers can execute automatically upon installation, delivering payloads such as backdoors, infostealers, cryptocurrency miners, botnet loaders, and ransomware. The abuse leverages Wallpaper Engine's feature that allows executable applications as wallpapers, which poses a security risk. Valve has removed identified malicious wallpapers, but new threats may emerge. Users are advised to download content only from trusted sources and scan downloaded files with updated antivirus software.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 06/16/2026, 18:30:30 UTC

Technical Analysis

Researchers at Kaspersky have identified that threat actors are exploiting the Wallpaper Engine application on Steam by uploading malicious wallpaper packages to the Steam Workshop. Wallpaper Engine supports application wallpapers that are executable Windows applications set as desktop backgrounds. Attackers embed malware payloads directly or within password-protected archives that execute automatically upon wallpaper installation. Malware families observed include DarkKomet backdoors, Lumma and Vidar infostealers, cryptocurrency miners, botnet loaders, RanEngine, and ransomware. The malicious wallpapers have been downloaded thousands of times before detection. Valve has removed known malicious wallpapers but the risk persists due to the platform's design and ongoing submissions.

Potential Impact

Successful installation of malicious wallpapers can lead to system compromise through backdoors, theft of Steam account credentials, unauthorized cryptocurrency mining, botnet participation, and ransomware infection. This impacts user privacy, system integrity, and potentially financial assets linked to Steam accounts or cryptocurrency wallets. The threat exploits a legitimate feature of Wallpaper Engine, increasing the risk of user deception and widespread infection.

Mitigation Recommendations

Valve has removed the known malicious wallpapers identified by researchers. Users should only download wallpapers from trusted sources on Steam Workshop and scan all downloaded content with up-to-date antivirus software before installation. There is no official patch for Wallpaper Engine's application wallpaper feature; users should exercise caution and consider disabling or avoiding application-type wallpapers. Monitor vendor advisories for updates on remediation or additional protective measures.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Article Source
{"url":"https://www.bleepingcomputer.com/news/security/steam-workshop-abused-to-spread-malware-via-wallpaper-engine-app/","fetched":true,"fetchedAt":"2026-06-16T18:30:24.049Z","wordCount":763}

Threat ID: 6a3196400b89be68880898c1

Added to database: 6/16/2026, 6:30:24 PM

Last enriched: 6/16/2026, 6:30:30 PM

Last updated: 6/17/2026, 5:03:46 AM

Views: 20

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses