P
Back to articles
News3 min read

Kaspersky finds malware hidden in Steam Wallpaper Engine that hijacks accounts to spread itself — dozens of malicious packages downloaded tens of thousands of times

Kaspersky researchers uncover a months-long malware campaign exploiting Steam's Wallpaper Engine executable wallpaper feature, with dozens of malicious packages downloaded tens of thousands of times to deliver infostealers and ransomware.

Source: Tom's Hardware
Kaspersky finds malware hidden in Steam Wallpaper Engine that hijacks accounts to spread itself — dozens of malicious packages downloaded tens of thousands of times

The Hidden Danger in Your Desktop: How Attackers Turned Steam Wallpapers into Malware Delivery Vehicles

For months, a sophisticated malware campaign has been hiding in plain sight on one of Steam's most popular non-gaming applications. Kaspersky researchers have uncovered a supply-chain attack that weaponized Wallpaper Engine's executable wallpaper feature, turning animated desktop backgrounds into delivery vehicles for infostealers, crypto miners, and ransomware. The campaign, which began in late 2025, has already seen dozens of malicious packages downloaded tens of thousands of times before removal.

The Weapon: Wallpaper Engine's Application Wallpaper Feature

Wallpaper Engine, a $4.99 utility that ranks among Steam's most-used non-game titles with 93,000 to 114,000 concurrent users and nearly a million reviews, supports four wallpaper types. One of them—the "application wallpaper"—is a standalone executable Windows program that runs as the desktop background. This legitimate feature became the attack vector.

Unlike static images or video wallpapers, application wallpapers are full Windows executables. When a user applies such a wallpaper, the executable runs with the user's permissions. Attackers realized they could embed malicious code directly alongside legitimate wallpaper files, or hide it inside password-protected archives that would auto-extract when the wallpaper was applied.

Two Delivery Methods, One Devastating Result

Kaspersky researchers Maxim Starodubov and Denis Brylev identified two primary delivery mechanisms. In the first, malicious EXE files, DLLs, or scripts sat directly alongside the legitimate wallpaper assets. In the second, more insidious approach, the payload was tucked inside a password-protected archive. The password was either embedded in the archive filename or stored in a JSON configuration file, allowing a script to automatically extract and execute the payload when the wallpaper was applied.

In a sample examined in December 2025, researchers observed a functional desktop game running while discreetly dropping a DarkKomet backdoor named `Synaptics.exe` and a tampered system library, `AggregatorHost.dll`. That library located the running Steam application, hunted for account credentials, hijacked the live session, and exfiltrated the data to a command-and-control server.

Self-Propagating Through Hijacked Accounts

The session hijacking capability is what makes this campaign particularly resilient. Control of an active Steam session allows attackers to post fresh malicious wallpapers under the victim's name. This creates a self-sustaining cycle: each compromised account becomes a new distribution node, which is why the campaign continues to regenerate after takedowns.

A Threat Actor Ecosystem, Not a Single Group

The malware payloads span a diverse toolkit: the DarkKomet backdoor, Lumma and Vidar infostealers, the RenEngine loader, cryptocurrency miners, and ransomware. Kaspersky attributes this variety to multiple independent threat groups piling onto the same technique rather than a single actor. This "technique adoption" model—where multiple groups independently exploit the same vulnerability—makes attribution difficult and mitigation more complex.

Geographic Concentration and User Demographics

Kaspersky placed 89% of malicious download attempts in China, followed by Russia at 5.5%, with smaller shares in Singapore, Hong Kong, Germany, Vietnam, India, and Canada. This concentration aligns with Wallpaper Engine's user base, which skews heavily toward Chinese gamers. The attackers understood their target audience and tailored distribution accordingly.

The Broader Steam Malware Landscape

This campaign doesn't exist in isolation. It follows a disturbing pattern of malware reaching players through Steam's ecosystem. Previous incidents include the `Synthesis` malware distributed through the Workshop on Christmas Day 2023, an Early Access game that shipped with three malware strains in July 2024, and a title that drained roughly $150,000 from players in September 2024. As of March 2025, researchers have cataloged a growing list of infected Steam games dating back to 2024.

Implications for Platform Security

The Wallpaper Engine case highlights a fundamental tension in platform design: features that enable user creativity and customization also create attack surface. Steam's Workshop and similar user-generated content platforms must balance openness with security. Valve has taken steps to scan Workshop submissions, but the executable wallpaper feature presents a unique challenge—it's a legitimate, documented feature that happens to be exploitable.

For users, the lesson is clear: even popular, well-reviewed applications can become malware vectors when they execute user-supplied code. For platform operators, it's a reminder that any feature allowing arbitrary code execution—no matter how benign its intended purpose—requires rigorous isolation and monitoring.

Related Articles

Frontier Airlines site leaks all personal info with just a glance at a boarding pass, researcher claims — booking number and last name nets you every passenger's personal info, including address, passport, TSA PreCheck, and most credit card info
News4 min

Frontier Airlines site leaks all personal info with just a glance at a boarding pass, researcher claims — booking number and last name nets you every passenger's personal info, including address, passport, TSA PreCheck, and most credit card info

Security researcher Bob reveals Frontier Airlines exposed passenger passport data, credit card info, and TSA PreCheck numbers through a simple API flaw — just a boarding pass code and last name.

Hardware
Chinese memory brands ditch Samsung and Micron for homegrown CXMT and YMTC silicon — Corsair, HP, and Dell are already adopting the China-produced DDR5 chips
News4 min

Chinese memory brands ditch Samsung and Micron for homegrown CXMT and YMTC silicon — Corsair, HP, and Dell are already adopting the China-produced DDR5 chips

Chinese memory brands Gloway and KingBank ditch Samsung and Micron for homegrown CXMT DDR5 chips, with Corsair, HP, and Dell already adopting the China-produced memory modules.

Hardware
AMD silently removes memory encryption from consumer Ryzen CPUs, leaving users unaware that they may be vulnerable — security feature vanishes after newer AGESA firmware, AMD engineers go radio silent when pressed about the change
News3 min

AMD silently removes memory encryption from consumer Ryzen CPUs, leaving users unaware that they may be vulnerable — security feature vanishes after newer AGESA firmware, AMD engineers go radio silent when pressed about the change

AMD quietly disabled Transparent Secure Memory Encryption (TSME) on consumer Ryzen CPUs through AGESA 1.2.7.0 firmware updates. AMD engineers went silent when pressed for answers.

Hardware
China drafts $295 billion plan to build national AI data center grid running on 80% homemade silicon — projected 2028 timeline could run into limits of local chip production
Review5 min

China drafts $295 billion plan to build national AI data center grid running on 80% homemade silicon — projected 2028 timeline could run into limits of local chip production

China is drafting a $295 billion (2 trillion yuan) plan to build a nationwide AI data center grid by 2028, requiring 80% of chips to be domestically produced. SMIC's 7nm-class process is already at 93% utilization, HBM memory bottlenecks constrain Huawei's Ascend production, and industry estimates show China trails leading-edge semiconductor tech by 5-10 years.

Hardware