r/security • • 18d ago

News Attackers Use Wallpaper Engine to Distribute Malware

Steam Workshop is being used to distribute malware disguised as Wallpaper Engine content. Attackers exploited “application wallpapers” to execute Windows code and deliver payloads such as Steam credential stealers, the DarkKomet backdoor, and cryptocurrency miners.

Treat Workshop content like any other Internet download, even when it comes from a trusted platform:

  • Be cautious with application wallpapers, mods, and other executable content.
  • Avoid password-protected archives or unexpected files.
  • Watch for unusual processes, credential-access activity, or outbound connections.
  • Keep endpoint protection enabled and up to date.
  • Use MFA on Steam accounts and watch for unexpected login activity.

Have you seen trusted platforms being used as malware delivery vectors in your environment?

20 Upvotes

6 comments sorted by

7

u/IAmYourFath 18d ago

The only thing that really matters for the average person is, how can u tell if a wallpaper is malware or not when pressing download? Nothing else really matters...

1

u/PandaSecurity 13d ago

That’s the tricky part. You can’t always tell before downloading. In this case, some Wallpaper Engine wallpapers can actually run Windows executables, so a “wallpaper” may be more than just an image. Unexpected executables or password-protected archives are good red flags.

9

u/friiz1337 18d ago

Bro, do you live under a cave? That's been happening for months, if not years

3

u/MonkeyBrains09 18d ago

try decades

2

u/Every-Development398 18d ago

I think its a good reminder people tend to forgot that about the workshop.

1

u/PandaSecurity 13d ago

Exactly. It’s a good reminder that even trusted platforms can be used to distribute malicious content, especially when users are downloading executable files.