Kaspersky finds malware hidden in Steam Wallpaper Engine that hijacks accounts to spread itself — dozens of malicious packages downloaded tens of thousands of times

Steam Hardware Survey April 2022
(Image credit: Valve)

Attackers have spent the past several months smuggling malware into Steam through animated desktop wallpapers, hijacking the accounts of victims who install them and then using those stolen accounts to upload more infected files. That’s according to Kaspersky researchers Maxim Starodubov and Denis Brylev, who recently authored a report published on Securelist. Per the report, the malware campaign has been running since late last year and focuses on gamers in China, pushing everything from credential stealers to crypto miners and ransomware. Kaspersky found dozens of malicious packages, some downloaded tens of thousands of times before removal.

The culprit is Wallpaper Engine, a $4.99 live wallpaper tool that ranks among Steam's most-used non-game titles, with 93,000 to 114,000 concurrent users and nearly a million reviews. The app supports four wallpaper types, and one of them, the "application wallpaper," is a standalone executable Windows program that runs as the desktop background. That also makes it a pathway for third-party code to execute on a user's machine, which is exactly what attackers exploited.

Kaspersky observed two delivery methods. In some packages, the malicious EXE files, DLLs, or scripts sat directly alongside the legitimate wallpaper files. In others, the payload was tucked inside a password-protected archive, with the password either embedded in the archive name or in a JSON config file, allowing a script to open it automatically. Applying the wallpaper triggered the payload.

Latest Videos From

In a sample examined last December, the researchers managed to boot a functional desktop game while discreetly dropping a DarkKomet backdoor named Synaptics.exe and a tampered system library, AggregatorHost.dll. That library locates the running Steam app, hunts for account credentials, hijacks the live session, and ships the data to a command-and-control server. Control of an active session lets the attackers post fresh malicious wallpapers under the victim's name, which is why the campaign keeps regenerating after takedowns.

Kaspersky placed 89% of malicious download attempts in China, followed by Russia at 5.5% and smaller shares in Singapore, Hong Kong, Germany, Vietnam, India, and Canada. That concentration aligns with the wider Wallpaper Engine user base, which skews heavily toward China. Payloads spanned the DarkKomet backdoor, the Lumma and Vidar infostealers, the RenEngine loader, miners, and ransomware, a spread the researchers attributed to multiple independent groups piling onto the same technique rather than a lone threat actor or group.

This follows a run of malware reaching players through Valve's storefront over the past few years. A compromised Slay the Spire mod was distributed through the Workshop on Christmas Day 2023, the Chemia Early Access game shipped with three malware strains in July last year, and the BlockBlasters title drained roughly $150,000 from players in the following September. As of March, the FBI was seeking victims of infected Steam games dating back to 2024.

Google Preferred Source

Follow Tom's Hardware on Google News, or add us as a preferred source, to get our latest news, analysis, & reviews in your feeds.

TOPICS
Luke James
Contributor

Luke James is a freelance writer and journalist.  Although his background is in legal, he has a personal interest in all things tech, especially hardware and microelectronics, and anything regulatory. 

  • flytrap23
    And that is still in the Steam Store.
    Reply
  • JTWrenn
    Wait...people paid $5 for a wallpaper app. That's pretty wild.
    Reply
  • USAFRet
    Wallpaper application spewing malware?
    What is this, last century?
    Reply
  • Eximo
    People did used to buy backgrounds and screensavers on disk. Last century indeed, though a lot of that slopware survived into the early 2000s as well. Always a group that was behind the curve and didn't know how to find things on the internet.

    One of my earliest troubleshooting wins. Why was the Win 95 computer crashing, but only unattended? Multiple screen saver packages of course.
    Reply
  • usertests
    Yandere anime waifu
    Reply
  • Nuclear Joestar
    Admin said:
    Attackers have spent the past several months smuggling malware into Steam through animated desktop wallpapers.

    Kaspersky finds malware hidden in Steam Wallpaper Engine that hijacks accounts to spread itself — dozens of malicious packages downloaded tens of t... : Read more
    My guy i know that you are absolutely lying about this. The U.S. government banned Kaspersky software due to severe national security risks associated with the company's Russian origins. Officials determined that the Russian government could legally compel Kaspersky to hand over sensitive customer data or exploit the antivirus’s deep system access to conduct cyber espionage or deploy malware.
    No, it is no longer safe to use—or it has been rendered entirely ineffective—depending on where you live.

    In the United States: Kaspersky is completely banned due to national security concerns. The software has stopped receiving critical updates and virus patches. Leaving it installed leaves your system entirely vulnerable to new malware. Product Shutdown: Kaspersky products have been blocked from operating effectively within the U.S.. Many former U.S. customers had their services forcibly uninstalled and replaced with an alternative provider (UltraAV).
    Security.org +3


    Purchase Restrictions:You cannot buy a new license or renew an existing subscription if you are located in the U.S.
    .
    Alternatives: Since Kaspersky no longer provides the security updates required to protect your devices from modern threats, users are advised to switch to other widely recognized antivirus solutions like Bitdefender or ESET
    if your still using kapersky then most likley that is the one giving you the virus i recomend you research banned antivirus softwares

    on top of that
    both Valve Corporation (the developer) and its digital storefront, Steam, are located in the United States. Their global corporate headquarters and primary operations are based in Bellevue, WashingtonWhile the company is centrally controlled from the US, their digital services and physical products (like the Steam Deck) are distributed worldwide.
    Reply
  • JohnyFin
    Warning!
    DON'T use Kaspersky. This pseudo antivirus is very dangerous for your security! It contains hidden exploits from Kreml for spaying and other dangerous things
    Reply
  • edzieba
    So wallpaper engine could just drop and execute downloaded .exes and .dlls directly into a user environment and execute them, and this obvious payload delivery mechanism was allowed on Steam why? That's a tailor-made malware distribution and deployment mechanism helpfully hosted and operated by someone else.
    Nuclear Joestar said:
    1) The world outside the US exists.
    2) This report is from Kasperksy Research, so the functioning of a specific piece of antivirus software is a single nation is irrelevant.
    Reply
  • MJS WARLORD
    I dumped kaspersky the day ukraine got invaded
    Reply
  • thesyndrome
    JTWrenn said:
    Wait...people paid $5 for a wallpaper app. That's pretty wild.
    I did, because I wanted animated wallpapers.

    I've paid more for a sandwich that I didn't enjoy, and that was eaten in less than 10 minutes, so by comparison the hours that I've had enjoyable animated backgrounds with relaxing music that I can set on a customised playlists and roations and set individually for each of my monitors isn't such a bad deal.
    Reply