Kaspersky Reveals Malware Abused Steam Workshop Wallpaper Engine, Stealing Thousands of Gamer Accounts

Kaspersky reported that the campaign’s victims were overwhelmingly concentrated in China: 89% of targets were located there, and it highlighted Wallpaper Engine’s scale—nearly one million reviews and about 100,000 daily active users—making its Steam Workshop distribution unusually attractive for attackers.
Kaspersky described two primary delivery methods for weaponized Wallpaper Engine “application” wallpapers: (1) the visible wallpaper archive contained malicious executables/DLLs/scripts alongside the apparent application, and (2) malware was hidden in password-protected archives where either users were tricked into entering the password or the password was automatically extracted from the archive filename or a bundled JSON configuration.
The analysis included concrete example payload behavior: once an infected wallpaper was launched, it could drop “Synaptics.exe” (linked to the DarkKomet remote access trojan family) into C:\ProgramData\Synaptics\, while a secondary executable named “._cache_GAME1.exe” was used to load the decoy game experience (NTRaholic) to keep the wallpaper appearing normal.
In describing the scope, one report quoted Kaspersky directly: “We discovered dozens of these malicious application wallpapers floating around Steam Workshop, and each one had already been downloaded thousands – or even tens of thousands – of times,” emphasizing how long many infected items remained in circulation before being identified.
Hackers hid malware inside fake animated wallpapers on Steam Workshop, targeting users of Wallpaper Engine — a desktop customization app with nearly one million reviews and around 100,000 daily active users. Kaspersky discovered dozens of these poisoned wallpapers, many already downloaded thousands or even tens of thousands of times before anyone caught them.
Steam itself was not hacked. Instead, attackers exploited the platform's open content-sharing system to upload wallpapers that ran malicious code the instant a user applied them. The campaign, active since late 2025, hit gamers primarily in China — which accounted for 89% of all victims — and to a lesser extent in Russia.
Wallpaper Engine supports four content types: videos, scenes, web pages, and applications. The "application" format is the dangerous one. Unlike a video file, an application wallpaper is a Windows executable — a program that runs. GBHackers explained that attackers used this format to drop malware the moment a user applied a wallpaper, with no extra clicks required.
Once launched, the infected wallpaper dropped a file called "Synaptics.exe" into C:\ProgramData\Synaptics\. That file is linked to DarkKomet, a well-known remote access trojan that lets attackers control a victim's machine. A second hidden program, "._cache_GAME1.exe," ran a decoy game called NTRaholic. This kept the wallpaper looking normal while the malware worked in the background, according to Kaspersky.
Attackers used two main methods to sneak malware past Steam's automated checks. The first was simple: malicious files like DLLs and scripts were bundled directly alongside the fake wallpaper. The second was more clever. Malware was hidden inside password-protected archives, according to Dexerto. Steam's scanners can't open locked archives, so the files passed inspection.
To get users to open those locked archives, attackers either tricked them into typing in a password or hid the password inside the filename itself. Once unlocked, the archive dropped payloads including the Lumma and Vidar credential stealers, crypto miners, and a patched system file designed to steal Steam session tokens and take over accounts. Protos noted that this shift showed attackers specifically adapting to Steam's defenses.
The campaign was not a random spray of malware. Attackers built specific lures for a specific audience. Many of the infected wallpapers were disguised as the adult-themed game NTRaholic, a title popular in Asian gaming markets. This strategy made victims less likely to question why an adult game was packaged as a wallpaper, according to Kaspersky.
The geographic focus was striking. Of all confirmed victims, 89% were in China, with smaller shares in Russia, Singapore, and Germany. Talkesport noted that Wallpaper Engine's enormous user base — roughly 100,000 people open it every day — made Steam Workshop an unusually attractive distribution channel for attackers looking to reach a large audience fast.
Valve moved to remove the identified malicious wallpapers after Kaspersky published its findings on June 16, 2026. But security researchers say the damage was already done. Kaspersky stated directly: "We discovered dozens of these malicious application wallpapers floating around Steam Workshop, and each one had already been downloaded thousands — or even tens of thousands — of times." Many had been live for months.
Experts are now calling on Valve to sandbox the application wallpaper format or remove it entirely. Out of roughly 700,000 Wallpaper Engine items on Steam Workshop, only about 2,000 are the dangerous application type. GBHackers and other outlets argue that if a platform allows executable sharing, it needs far stronger vetting — not just automated scans that password-protected archives can beat. Until then, users should check creator reputation and community reviews before downloading any Workshop content.
Publishers
11
Articles
2
Reach
13