MilikMilik

Thousands of Steam Users Hit by Malware Hidden in Anime Wallpapers

Thousands of Steam Users Hit by Malware Hidden in Anime Wallpapers
Interest|High-Quality Software

What the Wallpaper Engine Malware Campaign Is and Why It Matters

The Wallpaper Engine malware campaign is a long-running attack where cybercriminals hide Windows executable malware inside Steam Workshop wallpapers, using lively anime-style backgrounds to infect users’ PCs, steal Steam account credentials, and install persistent backdoors without obvious warning signs. Kaspersky researchers report that threat actors have abused Wallpaper Engine’s “Application Wallpaper” feature for about a year, slipping malicious .exe, .dll, and script files into community-made wallpapers that run as soon as users apply them. These wallpapers often appear legitimate, complete with working mini-games or interactive widgets, so victims see a normal customization tool while their systems are compromised in the background. This is a clear case of Steam malware distribution spreading through user-generated content rather than a flaw in the core app itself, and it shows how attractive platforms with executable customization features have become for attackers.

Thousands of Steam Users Hit by Malware Hidden in Anime Wallpapers

How Steam Malware Distribution Exploits Application Wallpapers

Wallpaper Engine’s Application Wallpaper feature is at the center of this security problem because it allows wallpapers to run as standalone Windows executable programs. That flexibility is powerful: creators can build mini-games, planners, system monitors, or interactive scenes. It also opens a path for Windows executable malware when Workshop items include hidden payloads that launch the moment a wallpaper is applied. According to Kaspersky, attackers used two main delivery methods: first, archives bundling the legitimate executable wallpaper alongside compromised .exe files, DLLs, or scripts; second, password-protected archives where the password is written directly in the filename, encouraging users to open them. Once started, these wallpapers automatically run the malicious components with the same trust and permissions as normal desktop software, bypassing many users’ expectations about what a “wallpaper” can do and turning a cosmetic Steam add-on into a vehicle for backdoor installation.

What the Malware Does: Account Theft and Backdoor Installation

The malicious wallpapers do more than display anime scenes; they behave like full malware toolkits focused on Steam account theft and long-term access. In one investigated sample, a wallpaper posing as a game named NTRaholic ran smoothly from a user’s perspective, while silently dropping a backdoor called Synaptics.exe from the DarkKomet family. Another component, AggregatorHost.dll, carried a payload that harvested Steam session data and other credentials, then sent them to the attackers’ command-and-control server. Once they had live session access, attackers could hijack accounts, upload new malicious wallpapers, and expand the campaign. Other samples delivered infostealers like Lumma and Vidar, plus loaders such as RenEngine, crypto-miners, and ransomware. This combination of credential theft and backdoor installation means a single wallpaper can both steal logins and keep a persistent foothold on a victim’s machine.

Who Was Affected and How Widespread the Campaign Became

Kaspersky’s analysis shows that this Wallpaper Engine security issue is not a small, isolated incident but a broad Steam malware distribution campaign. Researchers identified dozens of malicious application wallpapers on Steam Workshop, each gathering thousands to tens of thousands of downloads before removal. One quotable finding is that “about 89% of malicious downloads targeted users in China, with Russia at roughly 5.5%, plus victims across Singapore, Germany, Vietnam, and Canada,” underscoring that the attack had a global footprint despite focusing on certain regions. The campaign has been active since late 2025, and new infected uploads continued to appear even after Valve removed earlier ones. Multiple independent threat actors exploited the same vector, suggesting that once the Application Wallpaper feature was recognized as a viable path, different groups reused it for account hijacking, backdoor installation, and monetization through infostealers and miners.

How Steam Users Can Stay Safe While Using Wallpaper Engine

Staying safe does not require abandoning Wallpaper Engine, but it does demand treating Application Wallpapers like any other executable software. Users should avoid Steam Workshop items that bundle extra .exe, .dll, or script files beyond what a simple wallpaper needs and treat password-protected wallpaper archives as an immediate red flag. Sticking to established creators with long, positive histories and reading community feedback helps reduce risk. Running a reliable security suite, such as Microsoft Defender, can detect many known threats before they run. Enabling Steam Guard, using unique passwords, and monitoring for unusual login activity add another layer of protection against Steam account theft. If anything suspicious occurs after applying a new wallpaper, log out of Steam on all devices, run a full malware scan from a clean system, and remove any untrusted wallpapers from your Workshop subscriptions.

Milik earns a commission when you shop through our links, at no extra cost to you. This article was generated with AI from published sources and product data.

You May Also Like

Comments
Say something...
No comments yet. Be the first to share your thoughts!