Kaspersky finds malware hidden in Steam Wallpaper Engine that hijacks accounts to spread itself — dozens of malicious packages downloaded tens of thousands of times
Kaspersky researchers uncover a months-long malware campaign exploiting Steam's Wallpaper Engine executable wallpaper feature, with dozens of malicious packages downloaded tens of thousands of times to deliver infostealers and ransomware.

The Hidden Danger in Your Desktop: How Attackers Turned Steam Wallpapers into Malware Delivery Vehicles
For months, a sophisticated malware campaign has been hiding in plain sight on one of Steam's most popular non-gaming applications. Kaspersky researchers have uncovered a supply-chain attack that weaponized Wallpaper Engine's executable wallpaper feature, turning animated desktop backgrounds into delivery vehicles for infostealers, crypto miners, and ransomware. The campaign, which began in late 2025, has already seen dozens of malicious packages downloaded tens of thousands of times before removal.
The Weapon: Wallpaper Engine's Application Wallpaper Feature
Wallpaper Engine, a $4.99 utility that ranks among Steam's most-used non-game titles with 93,000 to 114,000 concurrent users and nearly a million reviews, supports four wallpaper types. One of them—the "application wallpaper"—is a standalone executable Windows program that runs as the desktop background. This legitimate feature became the attack vector.
Unlike static images or video wallpapers, application wallpapers are full Windows executables. When a user applies such a wallpaper, the executable runs with the user's permissions. Attackers realized they could embed malicious code directly alongside legitimate wallpaper files, or hide it inside password-protected archives that would auto-extract when the wallpaper was applied.
Two Delivery Methods, One Devastating Result
Kaspersky researchers Maxim Starodubov and Denis Brylev identified two primary delivery mechanisms. In the first, malicious EXE files, DLLs, or scripts sat directly alongside the legitimate wallpaper assets. In the second, more insidious approach, the payload was tucked inside a password-protected archive. The password was either embedded in the archive filename or stored in a JSON configuration file, allowing a script to automatically extract and execute the payload when the wallpaper was applied.
In a sample examined in December 2025, researchers observed a functional desktop game running while discreetly dropping a DarkKomet backdoor named `Synaptics.exe` and a tampered system library, `AggregatorHost.dll`. That library located the running Steam application, hunted for account credentials, hijacked the live session, and exfiltrated the data to a command-and-control server.
Self-Propagating Through Hijacked Accounts
The session hijacking capability is what makes this campaign particularly resilient. Control of an active Steam session allows attackers to post fresh malicious wallpapers under the victim's name. This creates a self-sustaining cycle: each compromised account becomes a new distribution node, which is why the campaign continues to regenerate after takedowns.
A Threat Actor Ecosystem, Not a Single Group
The malware payloads span a diverse toolkit: the DarkKomet backdoor, Lumma and Vidar infostealers, the RenEngine loader, cryptocurrency miners, and ransomware. Kaspersky attributes this variety to multiple independent threat groups piling onto the same technique rather than a single actor. This "technique adoption" model—where multiple groups independently exploit the same vulnerability—makes attribution difficult and mitigation more complex.
Geographic Concentration and User Demographics
Kaspersky placed 89% of malicious download attempts in China, followed by Russia at 5.5%, with smaller shares in Singapore, Hong Kong, Germany, Vietnam, India, and Canada. This concentration aligns with Wallpaper Engine's user base, which skews heavily toward Chinese gamers. The attackers understood their target audience and tailored distribution accordingly.
The Broader Steam Malware Landscape
This campaign doesn't exist in isolation. It follows a disturbing pattern of malware reaching players through Steam's ecosystem. Previous incidents include the `Synthesis` malware distributed through the Workshop on Christmas Day 2023, an Early Access game that shipped with three malware strains in July 2024, and a title that drained roughly $150,000 from players in September 2024. As of March 2025, researchers have cataloged a growing list of infected Steam games dating back to 2024.
Implications for Platform Security
The Wallpaper Engine case highlights a fundamental tension in platform design: features that enable user creativity and customization also create attack surface. Steam's Workshop and similar user-generated content platforms must balance openness with security. Valve has taken steps to scan Workshop submissions, but the executable wallpaper feature presents a unique challenge—it's a legitimate, documented feature that happens to be exploitable.
For users, the lesson is clear: even popular, well-reviewed applications can become malware vectors when they execute user-supplied code. For platform operators, it's a reminder that any feature allowing arbitrary code execution—no matter how benign its intended purpose—requires rigorous isolation and monitoring.


