Kaspersky researchers have uncovered an ongoing malware distribution campaign leveraging Steam Workshop and Wallpaper Engine, a popular Steam application used to create and share animated desktop wallpapers. Researchers identified multiple infected wallpaper packages which had accumulated thousands of downloads. Steam users in China and Russia were primarily targeted, with other victims located in Singapore, Hong Kong, Germany, Vietnam, India and Canada. The main goal of the attackers was stealing gaming accounts and deploying additional malware.
Steam Workshop is a built-in feature of the Steam gaming platform that allows users to easily find, install, and manage user-generated content like mods, custom maps, game items, and wallpapers. The Wallpaper Engine app supports several wallpaper formats, including videos, interactive scenes, web pages, and applications.
The application-based wallpaper feature allows executable programs to run directly on a user's Windows computer, allowing attackers to distribute malicious software under the guise of legitimate content. Kaspersky identified dozens of infected wallpaper packages available through Steam Workshop. Many of these packages had thousands or even tens of thousands of downloads.
There were two primary delivery methods that attackers used. In some cases, malicious executable files, DLLs, and scripts were bundled directly with the wallpaper package. In others, attackers hid malware inside password-protected archives, with passwords embedded in archive names or configuration files. Once the wallpaper was installed, malicious payloads executed automatically.
For example, one of the malicious wallpaper samples discovered in December 2025 appeared to function legitimately at first, launching an embedded desktop game without any visible signs of compromise. In the background, however, the wallpaper deployed the DarkKomet backdoor and installed a modified library designed to target Steam users: it harvested account information and hijacked active Steam sessions.
image
The attacks were likely conducted by multiple independent threat actors rather than a single group, and were not limited to a single malware family. Across multiple cases, Kaspersky detected malicious wallpapers distributing Lumma and Vidar infostealers and the RenEngine loader. Kaspersky's security solutions detect and block all malware associated with this campaign.
"Trusted platforms can be abused to distribute malware: the attacks rely on users trusting content hosted within legitimate ecosystems. While many of the malware families involved are well-known, the delivery mechanism enables attackers to reach large numbers of potential victims through seemingly harmless content," commented Maxim Starodubov, a cybersecurity expert at Kaspersky.
Detailed information is available in a report on Securelist.
That supposed detailed information: https://securelist.com/dozens-of-malicious-wallpapers-found-on-steam-workshop/120186/
When we analyzed them, we caught two different methods the attackers were using to spread their malware:
An archive containing the executable wallpaper alongside the malicious files. This payload usually consisted of compromised EXE files, DLLs, or malicious scripts. In other cases, attackers threw a curveball by hiding the malware inside a password-protected archive. Either the victim was tricked into typing the password, or a script handled it automatically. The attackers would hide the password in plain sight – either right in the archive’s name or inside a JSON configuration installed along with other wallpaper files. For all the other variations, the payload triggered automatically when the user selected and applied the wallpaper.
Inside an infected game wallpaper
Main screen of the wallpaper application
On the surface, this wallpaper sample (above) we uncovered in December 2025 looks completely harmless. Once launched, there’s absolutely nothing to trigger your suspicion. The built-in game boots up flawlessly, runs smoothly, and the desktop controls work exactly as they should. But behind the scenes, a full-blown infection is underway. Within just a few minutes, a user might suddenly realize their Steam account has been hijacked, or find their computer crippled by malware, with their files being encrypted by ransomware or their system performance tanking because of a hidden crypto miner. How the malware deploys
Once the game wallpaper launches, it drops a backdoor file called Synaptics.exe (part of the DarkKomet malware family) straight into the victim’s system. At the same time, an executable named ._cache_GAME1.exe fires up to boot the actual game, NTRaholic.
But that ._cache_GAME1.exe module is doing double duty. It simultaneously installs a custom version of a system library called AggregatorHost.dll with a payload inside. This modified library has one main objective: track down the Steam app on the computer and hunt for account credentials. Looking for the Steam app
Next, the modified library hijacks the user’s live Steam session. Hijacking the Steam session
Hijacking the Steam session
After that, the compromised AggregatorHost.dll sends all the collected data to a server controlled by the hackers at hxxp://120.48.156[.]17/ey.php. Once the attackers have control of that active session, they can use the victim’s account to upload even more malicious wallpapers to Steam Workshop. Attribution and victims
The game wallpaper described above is just one flavor of the many variations we uncovered during our research. By weaponizing the application wallpaper feature, bad actors have successfully distributed almost every type of malware under the sun – from popular infostealers and backdoors to crypto miners and botnet loaders.
Because the range of tools being used is so diverse, we suspect this isn’t the work of a single mastermind. Instead, it looks like multiple scattered, independent hacking groups are all jumping on the same trend. Right now, the primary targets are gamers in China. The wallpaper art styles and titles are tailored specifically to them, and the data backs it up: our security systems caught a staggering 89% of the malicious download attempts happening right there. That said, there’s absolutely nothing stopping these attackers from pivoting and launching a similar campaign in any other part of the world. Russia comes in second place for total downloads at 5.5%, followed by a smattering of other countries and territories: Singapore (1.4%), Hong Kong (0.9%), Germany (0.9%), Vietnam (0.9%), India (0.5%), and Canada (0.5%).
Malicious app wallpaper downloads by region How to stay safe
Our investigation proves that even trusted platforms like the Steam Workshop aren’t completely safe from malware. In most cases, we caught old, familiar threats such as DarkKomet, the Lumma and Vidar infostealers, and the RenEngine loader. Kaspersky solutions can easily spot and block all of these payloads, no matter how clever the packaging is, thanks to our proactive security layers. Here are some of the specific threat detection verdicts assigned to the objects we discovered during our research:
By the time this post went live, the Steam team had already scrubbed the identified malicious wallpapers and links from the platform. However, given how frequently new infected wallpapers keep popping up on the Steam Workshop, you shouldn’t rely on Steam to catch everything. It’s highly recommended to run an antivirus scan on these types of wallpapers before you actually apply them. Indicators of compromise
Anonymous · 2026-06-20 15:46 [#3947][report] Pretty wild that Steam allows such a thing to continue for so long.
yp22 · 2026-06-21 00:16 [#3948][report] I have a feeling this is one of those cases, where they were warned about it before by someone. Like "Hey guys, there's this terrible vulnerability that's definitely going to be exploited one day. You need to fix it before that happens" >>As early as August 2025 as expected
OH WOW YOU CAN PUT MALWARE ON THE STUFF THAT PEOPLE DOWNLOAD WHO COULD HAVE SEEN THAT ONE COMING.