A Steam malware campaign has been uncovered by researchers targeting users through infected desktop wallpapers. Specifically, attackers are abusing the Steam Workshop and the Wallpaper Engine application to distribute malicious software disguised as animated backgrounds. Consequently, these infected packages have accumulated thousands of downloads globally.

The Steam malware campaign primarily targets users in China and Russia. However, researchers also identified victims in Singapore, Germany, India, and Canada. The main objective of the threat actors is stealing gaming accounts and deploying additional malicious payloads on compromised systems.

How the Steam malware campaign operates

Steam Workshop allows users to find and install user-generated content like mods and custom maps. Meanwhile, the Wallpaper Engine application supports interactive scenes and applications. This application-based feature allows executable programs to run directly on Windows computers, which creates a security risk.

Attackers used two primary delivery methods to infect systems. In some cases, malicious executable files and scripts were bundled directly with the wallpaper package. Alternatively, attackers hid malware inside password-protected archives with passwords embedded in configuration files.

Specific malware strains detected

One sample discovered in December 2025 launched an embedded desktop game to appear legitimate. In the background, however, the wallpaper deployed the DarkKomet backdoor to harvest account information and hijack active sessions. Notably, this allowed attackers to compromise the user’s gaming profile without their knowledge.

The attacks were conducted by multiple independent threat actors using various malware families. Across multiple cases, researchers detected the distribution of Lumma and Vidar infostealers alongside the RenEngine loader. Fortunately, security solutions can detect and block all malware associated with this campaign.

Expert analysis on platform abuse

“Trusted platforms can be abused to distribute malware: the attacks rely on users trusting content hosted within legitimate ecosystems. While many of the malware families involved are well-known, the delivery mechanism enables attackers to reach large numbers of potential victims through seemingly harmless content.”

Maxim Starodubov, cybersecurity expert at Kaspersky

Recommended security measures

To prevent infections from this Steam malware campaign, users should exercise caution when downloading any apps or user-generated content. Furthermore, verifying the reputation of content creators before installation is highly recommended. Finally, relying on proven security solutions remains essential to detect active threats.