Worked example · 2026-06
Steam Workshop / Wallpaper Engine malicious wallpapers — Lumma + Vidar infostealers harvesting Steam sessions and crypto wallets — Windows / cross-chain — disclosed 2026-06-16
Summary
On 2026-06-16 (with a 2026-06-17 update), Kaspersky's Securelist published "Dozens of malicious wallpapers found on Steam Workshop," documenting a campaign that abused Steam Workshop — the community content hub built into Steam — to distribute malware through the popular Wallpaper Engine application. Wallpaper Engine supports an "application" wallpaper type: standalone executable programs that run as animated desktop backgrounds. Attackers uploaded trojanised application wallpapers — many themed with female anime characters and titled to appeal to the target audience — so that applying the wallpaper executes the bundled payload automatically.
Across the identified packages Kaspersky detected a broad toolbox: the Lumma and Vidar infostealers and the RenEngine loader, the DarkKomet backdoor, crypto miners, ransomware variants, and Python-based droppers/trojans. The infostealers harvest Steam account credentials and hijack active Steam sessions, exfiltrate browser data, and steal cryptocurrency-wallet information. Payloads were delivered either bundled directly in the package or hidden inside password-protected archives whose password was embedded in the archive name or a bundled JSON configuration so the contents evaded pre-extraction scanning. Many packages had thousands — or even tens of thousands of downloads, and Kaspersky assessed the activity as the work of multiple threat actors.
The campaign had been active since at least August 2025. Kaspersky highlighted a December 2025 sample in which a wallpaper appeared to launch a legitimate desktop game (._cache_GAME1.exe) while silently dropping a DarkKomet backdoor (Synaptics.exe) and a compromised AggregatorHost.dll that targeted Steam app credentials and hijacked active sessions, beaconing to C2 at 120.48.156[.]17/ey.php. The findings extend a growing pattern of Steam-related malware abuse, following Prodaft's July-2025 report on the trojanised Early Access game Chemia (Hijack Loader + Fickle Stealer + Vidar targeting crypto wallets) and the FBI's 2026 investigation into malware-laden Steam games (Chemia, PirateFi, BlockBlasters, and others).
Timeline (UTC)
| When | Event | OAK ref |
|---|---|---|
| ≥ 2025-08 | Trojanised Wallpaper Engine "application" wallpapers present on Steam Workshop; applying a wallpaper auto-executes the bundled payload | T4.013 + T4.013.001 |
| 2025-12 | DarkKomet sample: wallpaper launches ._cache_GAME1.exe while dropping Synaptics.exe backdoor + AggregatorHost.dll; steals Steam credentials, hijacks sessions, C2 120.48.156[.]17/ey.php |
T4.013 (session-hijack + backdoor arm) |
| Through 2026-06 | Standing campaign: dozens of packages, thousands–tens-of-thousands of downloads each; Lumma/Vidar stealers + RenEngine loader, miners, ransomware; password-protected-archive delivery; 89% of attempts in China | T4.013 + T4.013.001 |
| 2026-06-16 | Kaspersky / Securelist discloses the campaign ("Dozens of malicious wallpapers found on Steam Workshop"); assesses multiple threat actors; publishes IOCs (update 2026-06-17) | (defender-side disclosure) |
Public references
[kasperskysteamwallpaper2026]— Kaspersky / Securelist, "Dozens of malicious wallpapers found on Steam Workshop" (2026-06-16, update 2026-06-17; Steam Workshop + Wallpaper Engine "application" wallpapers auto-executing Lumma/Vidar infostealers, RenEngine loader, DarkKomet backdoor, miners, ransomware, Python droppers; Steam credential + session-hijack + browser-data + crypto-wallet theft; bundled vs password-protected-archive delivery; thousands–tens-of-thousands of downloads per package; 89% China; active since ≥ Aug 2025; Dec-2025 DarkKometSynaptics.exe/AggregatorHost.dllC2120.48.156[.]17/ey.php): https://securelist.com/dozens-of-malicious-wallpapers-found-on-steam-workshop/120186/[bleepingsteamworkshop2026]— BleepingComputer, "Steam Workshop abused to spread malware via Wallpaper Engine app" (2026-06; secondary corroboration of the Kaspersky campaign — executable "application" wallpapers, infostealer/backdoor payloads, password-protected-archive delivery, China-concentrated targeting): https://www.bleepingcomputer.com/news/security/steam-workshop-abused-to-spread-malware-via-wallpaper-engine-app/[decryptsteamwallpaper2026]— Decrypt, "Anime Girls Could Steal Your Crypto as Wallpaper Malware Targets Steam Gamers" (2026-06-19; crypto-press coverage confirming Lumma/Vidar infostealers stealing cryptocurrency-wallet information, the Steam Workshop delivery channel, and the broader Steam-malware pattern incl. Chemia and the FBI investigation): https://decrypt.co/371632/anime-girls-steal-crypto-wallpaper-malware-targets-steam-gamers[prodaftchemia2025]— Prodaft / secondary coverage (BleepingComputer, Tom's Hardware), trojanised Steam Early Access game "Chemia" (2025-07; EncryptHub / LARVA-208; Hijack Loader + Fickle Stealer + Vidar Stealer targeting crypto wallets and user data, Telegram-fetched instructions) — independent prior anchor for the trusted-platform game-distribution delivery shape: https://www.bleepingcomputer.com/news/security/hacker-sneaks-infostealer-malware-into-early-access-steam-game/
Discussion
This campaign is the canonical 2026 anchor for OAK-T4.013 (Endpoint Infostealer Wallet-Material and Credential Exfiltration) and the field anchor for its trusted-platform content-channel delivery sub-shape (T4.013.001). It is worth contrasting carefully with the same-class siblings. Against T4.012 (clipper): a clipper needs the victim to transact and captures only that transfer's destination, whereas the Lumma/Vidar stealers here take the standing key material and session state off the endpoint — every wallet vault, wallet file, saved login, and session cookie present — so the attacker gains durable, independent control and realises value on its own schedule with no victim transaction required. Against T11.006 (seed at rest in third-party storage): T11.006's substrate is a cloud-backup or password-manager service compromised server-side; here the compromise is host-resident malware on the victim's own device. Against T15.003 / T15.004 (operator endpoint/credential): those scope enterprise hosts whose state controls a protocol or exchange signing surface, whereas this is the commodity consumer-endpoint shape — mass-distributed malware-as-a-service against individual wallet holders. The 2011 allInVain wallet.dat theft (see examples/2011-06-allinvain-first-major-bitcoin-theft.md) is the historical class anchor that was forced into T15 "broadly construed" for lack of this home.
The delivery innovation — and the part most worth tracking — is the abuse of a trusted first-party platform's user-generated-content channel. Wallpaper Engine's "application" wallpaper type is, by design, an executable that runs on the user's desktop; uploaded to Steam Workshop, it lets an attacker distribute arbitrary code under the trust users place in Steam community content, with auto-execution on apply and thousands–tens-of-thousands of installs per package. The password-protected-archive trick (password embedded in the filename or a bundled config) is a complementary evasion that defeats pre-extraction scanning. This shape is the natural companion to T4.012.002 (reputation-laundered fake-software distribution): both make a malicious download look legitimate, but where T4.012.002 manufactures a synthetic cross-platform reputation network, this rides a single, genuinely trusted platform's content feature. It also generalises across the 2025–2026 Steam-malware wave — the trojanised game Chemia (Prodaft, July 2025) and the FBI's 2026 investigation into PirateFi, BlockBlasters, and others — which is why OAK tracks T4.013.001 as a forward candidate pending consolidation of these anchors. Consistent with OAK's scoping of endpoint-malware incidents, the crypto-relevant primitive recorded here is the wallet-material/session harvesting; the surrounding general-malware facets — the RenEngine loader, DarkKomet backdoor, crypto miners, ransomware variants, and Python droppers — are delivery/operational context rather than separately-minted crypto-attack Techniques.