MilikMilik

Wallpaper Engine Malware Campaign Steals Steam Accounts and Installs Backdoors

Wallpaper Engine Malware Campaign Steals Steam Accounts and Installs Backdoors
Interest|High-Quality Software

What the Wallpaper Engine Malware Campaign Is and Why It Matters

The Wallpaper Engine malware campaign is a long-running attack where cybercriminals hide executable malware inside Steam Workshop wallpapers, using the app’s Application Wallpaper feature to steal Steam account credentials and deploy backdoors as soon as users apply malicious backgrounds to their desktops. Researchers report that threat actors have abused Wallpaper Engine’s popularity and its ability to run full Windows programs from Workshop items, including user-made games, utilities, planners, and system monitors. Instead of exploiting a software flaw, attackers exploit trust: people assume content from Steam Workshop is safe because it is tied to their Steam library. As a result, malicious wallpapers — often themed as anime scenes or mini-games — have been downloaded tens of thousands of times, turning a desktop customization app into a large-scale malware distribution platform and source of account credential theft.

Wallpaper Engine Malware Campaign Steals Steam Accounts and Installs Backdoors

How Steam Workshop Wallpapers Turn Into Executable Malware

Wallpaper Engine’s Application Wallpaper feature is at the core of this campaign. It allows Workshop wallpapers to contain .exe, .dll, and script files that run as standalone Windows applications when a wallpaper is applied. According to Kaspersky, “the application-based wallpaper feature allows executable programs to run directly on a user’s Windows computer, allowing attackers to distribute malicious software under the guise of legitimate content.” Malicious uploaders pack these files into archives that look like ordinary wallpaper bundles, then rely on automatic execution when the user activates the wallpaper. Some packages disguise themselves as harmless games, planners, calendars, or system utilities, offering working features to avoid suspicion. Behind the scenes, hidden components download and launch additional payloads, turning a live wallpaper into a stealth installer that uses the Steam Workshop ecosystem as a convenient, semi-trusted malware distribution platform.

Wallpaper Engine Malware Campaign Steals Steam Accounts and Installs Backdoors

From Anime Wallpapers to Account Theft and Backdoors

Security researchers have documented dozens of malicious wallpaper packages, many dressed up as colorful anime scenes or animated mini-games. One sample from December 2025 pretended to be an innocent desktop mini-game but silently dropped the DarkKomet backdoor while harvesting Steam session data. Another test wallpaper included a game called NTRaholic that appeared to run flawlessly, yet deployed a backdoor named Synaptics.exe and a malicious library AggregatorHost.dll in the background. Other Application Wallpapers have carried infostealers like Lumma and Vidar, the RenEngine loader, crypto-miners, and ransomware. Once executed, these payloads can steal account credentials, hijack live Steam sessions, and send stolen data to attacker-controlled servers. Because the wallpapers often function as advertised, victims have little reason to suspect they are running Steam Workshop malware instead of harmless desktop effects.

Wallpaper Engine Malware Campaign Steals Steam Accounts and Installs Backdoors

Abused Trust: How the Campaign Stayed Active for Over a Year

This campaign did not rely on a security hole in Steam or Wallpaper Engine; it relied on user trust and an open Workshop ecosystem. Over years, Steam Workshop has become a popular hub for sharing mods and wallpapers, which makes users more likely to assume that all subscribed content is safe. Cybercriminals started uploading malicious wallpapers in late 2025 and have kept going, with new infected packages appearing even after Valve removes older ones. Researchers identified dozens of malicious Application Wallpapers, some earning thousands to tens of thousands of downloads before takedown, which shows how quickly harmful content can spread when attached to a widely used app. Attackers also abused password-protected archives, sometimes embedding the password in the filename, so payloads could hide inside wallpaper files while still executing automatically once users applied them.

Wallpaper Engine Malware Campaign Steals Steam Accounts and Installs Backdoors

How to Use Wallpaper Engine Safely and Protect Your Steam Account

Users do not need to abandon animated backgrounds, but they must treat Steam Workshop as an untrusted content pool rather than a guaranteed-safe library. Before installing new wallpapers, examine creator profiles, ratings, and comments for warnings or suspicious behavior, and avoid Workshop items that prompt you to download extra files from outside Steam. Keep antivirus protection enabled so it can scan Application Wallpapers and block known infostealers and backdoors. Be cautious of wallpapers that advertise mini-games, system utilities, or planners, since these are more likely to rely on executable code. If your Steam account shows unknown logins or purchases, revoke active sessions and change your password immediately. Finally, prefer non-executable wallpapers when possible; disabling or limiting Application Wallpapers reduces exposure to Wallpaper Engine malware and narrows the attack surface for future Steam Workshop malware campaigns.

Milik earns a commission when you shop through our links, at no extra cost to you. This article was generated with AI from published sources and product data.

You May Also Like

Comments
Say something...
No comments yet. Be the first to share your thoughts!