OAK — OnChain Attack Knowledge

Worked example · 2026-06

Steam Workshop / Wallpaper Engine malicious wallpapers — Lumma + Vidar infostealers harvesting Steam sessions and crypto wallets — Windows / cross-chain — disclosed 2026-06-16

Loss
undisclosed. Kaspersky did not publish a victim count or an aggregate theft figure. Because the extraction primitive is per-victim wallet-material and session-credential harvesting across an unknown number of infected endpoints rather than a single on-chain drain, the realised loss is distributed and not centrally tabulated. The campaign's reach is measurable through its distribution counters: dozens of infected Wallpaper Engine packages were identified on Steam Workshop, "thousands — or even tens of thousands" of downloads per malicious wallpaper. By telemetry, 89% of blocked malicious-download attempts originated in China, followed by Russia (5.5%), Singapore (1.4%), Hong Kong / Germany / Vietnam (0.9% each), and India / Canada (0.5% each).
OAK Techniques observed
OAK-T4.013 (Endpoint Infostealer Wallet-Material and Credential Exfiltration — primary; the malicious wallpapers deploy Lumma and Vidar infostealers that harvest Steam account credentials and hijack live Steam sessions, exfiltrate browser data, and steal cryptocurrency-wallet information from the infected Windows endpoint. See techniques/T4.013-endpoint-infostealer-wallet-credential-exfiltration.md). OAK-T4.013.001 (trusted-platform content-channel malware distribution sub-shape — the load-bearing delivery shape: the payload is delivered through Steam Workshop's legitimate user-content channel via Wallpaper Engine's executable "application" wallpaper type, so it inherits the platform's trust; forward candidate tracked in TAXONOMY-GAPS). Cross-ref OAK-T4.010 (adjacent delivery — like the fake-tool/extension class it reaches victims by riding software they sought out, but the trust channel here is a first-party platform's UGC feature rather than a counterfeit extension; see techniques/T4.010-fake-security-tool-browser-extension-phishing.md). (Some packages also dropped ransomware variants and crypto miners; consistent with OAK's scoping these co-occurring general-malware payloads are recorded as delivery/operational context rather than separately-mapped value-extraction Techniques.)
Attribution
unattributed. Kaspersky assessed the activity as involving multiple distinct threat actors rather than a single group — consistent with commodity malware-as-a-service infostealers (Lumma, Vidar) operated by independent affiliates. No named operator or cluster was published; indicators are sample/package-level rather than operator identities.
Key teaching point
A trusted first-party platform's user-generated-content channel is an active-code trust boundary, and a commodity infostealer that reaches it takes the keys, not just one transaction. This campaign is a clean 2026 anchor for OAK-T4.013 on two axes. On the payload axis, Lumma and Vidar are commodity stealers that scrape standing wallet material and authentication state off the endpoint at rest — browser-extension wallet vaults, wallet files, saved logins, and session cookies that enable live Steam-session hijacking which bypasses passwords and MFA outright — so a single infection compromises every wallet and session present on the device and is monetised on the attacker's own schedule, with no on-chain authorisation event to detect. On the delivery axis, it abuses Wallpaper Engine's "application" wallpaper type — wallpapers that are standalone Windows executables — uploaded to Steam Workshop, so the payload auto-executes the moment the user applies the wallpaper and inherits the trust users extend to Steam community content. The actionable lessons are endpoint-and-platform-side: install community/UGC content only from sources you can verify and treat auto-executing "application" wallpapers as untrusted code; keep key material off general-purpose endpoints (hardware-wallet / air-gapped signing) so a stealer has nothing at rest to take; and treat any seed, key, or session that touched an infected host as burned — rotate to fresh keys on a clean device and invalidate all sessions.

Summary

On 2026-06-16 (with a 2026-06-17 update), Kaspersky's Securelist published "Dozens of malicious wallpapers found on Steam Workshop," documenting a campaign that abused Steam Workshop — the community content hub built into Steam — to distribute malware through the popular Wallpaper Engine application. Wallpaper Engine supports an "application" wallpaper type: standalone executable programs that run as animated desktop backgrounds. Attackers uploaded trojanised application wallpapers — many themed with female anime characters and titled to appeal to the target audience — so that applying the wallpaper executes the bundled payload automatically.

Across the identified packages Kaspersky detected a broad toolbox: the Lumma and Vidar infostealers and the RenEngine loader, the DarkKomet backdoor, crypto miners, ransomware variants, and Python-based droppers/trojans. The infostealers harvest Steam account credentials and hijack active Steam sessions, exfiltrate browser data, and steal cryptocurrency-wallet information. Payloads were delivered either bundled directly in the package or hidden inside password-protected archives whose password was embedded in the archive name or a bundled JSON configuration so the contents evaded pre-extraction scanning. Many packages had thousands — or even tens of thousands of downloads, and Kaspersky assessed the activity as the work of multiple threat actors.

The campaign had been active since at least August 2025. Kaspersky highlighted a December 2025 sample in which a wallpaper appeared to launch a legitimate desktop game (._cache_GAME1.exe) while silently dropping a DarkKomet backdoor (Synaptics.exe) and a compromised AggregatorHost.dll that targeted Steam app credentials and hijacked active sessions, beaconing to C2 at 120.48.156[.]17/ey.php. The findings extend a growing pattern of Steam-related malware abuse, following Prodaft's July-2025 report on the trojanised Early Access game Chemia (Hijack Loader + Fickle Stealer + Vidar targeting crypto wallets) and the FBI's 2026 investigation into malware-laden Steam games (Chemia, PirateFi, BlockBlasters, and others).

Timeline (UTC)

When Event OAK ref
≥ 2025-08 Trojanised Wallpaper Engine "application" wallpapers present on Steam Workshop; applying a wallpaper auto-executes the bundled payload T4.013 + T4.013.001
2025-12 DarkKomet sample: wallpaper launches ._cache_GAME1.exe while dropping Synaptics.exe backdoor + AggregatorHost.dll; steals Steam credentials, hijacks sessions, C2 120.48.156[.]17/ey.php T4.013 (session-hijack + backdoor arm)
Through 2026-06 Standing campaign: dozens of packages, thousands–tens-of-thousands of downloads each; Lumma/Vidar stealers + RenEngine loader, miners, ransomware; password-protected-archive delivery; 89% of attempts in China T4.013 + T4.013.001
2026-06-16 Kaspersky / Securelist discloses the campaign ("Dozens of malicious wallpapers found on Steam Workshop"); assesses multiple threat actors; publishes IOCs (update 2026-06-17) (defender-side disclosure)

Public references

  • [kasperskysteamwallpaper2026] — Kaspersky / Securelist, "Dozens of malicious wallpapers found on Steam Workshop" (2026-06-16, update 2026-06-17; Steam Workshop + Wallpaper Engine "application" wallpapers auto-executing Lumma/Vidar infostealers, RenEngine loader, DarkKomet backdoor, miners, ransomware, Python droppers; Steam credential + session-hijack + browser-data + crypto-wallet theft; bundled vs password-protected-archive delivery; thousands–tens-of-thousands of downloads per package; 89% China; active since ≥ Aug 2025; Dec-2025 DarkKomet Synaptics.exe/AggregatorHost.dll C2 120.48.156[.]17/ey.php): https://securelist.com/dozens-of-malicious-wallpapers-found-on-steam-workshop/120186/
  • [bleepingsteamworkshop2026] — BleepingComputer, "Steam Workshop abused to spread malware via Wallpaper Engine app" (2026-06; secondary corroboration of the Kaspersky campaign — executable "application" wallpapers, infostealer/backdoor payloads, password-protected-archive delivery, China-concentrated targeting): https://www.bleepingcomputer.com/news/security/steam-workshop-abused-to-spread-malware-via-wallpaper-engine-app/
  • [decryptsteamwallpaper2026] — Decrypt, "Anime Girls Could Steal Your Crypto as Wallpaper Malware Targets Steam Gamers" (2026-06-19; crypto-press coverage confirming Lumma/Vidar infostealers stealing cryptocurrency-wallet information, the Steam Workshop delivery channel, and the broader Steam-malware pattern incl. Chemia and the FBI investigation): https://decrypt.co/371632/anime-girls-steal-crypto-wallpaper-malware-targets-steam-gamers
  • [prodaftchemia2025] — Prodaft / secondary coverage (BleepingComputer, Tom's Hardware), trojanised Steam Early Access game "Chemia" (2025-07; EncryptHub / LARVA-208; Hijack Loader + Fickle Stealer + Vidar Stealer targeting crypto wallets and user data, Telegram-fetched instructions) — independent prior anchor for the trusted-platform game-distribution delivery shape: https://www.bleepingcomputer.com/news/security/hacker-sneaks-infostealer-malware-into-early-access-steam-game/

Discussion

This campaign is the canonical 2026 anchor for OAK-T4.013 (Endpoint Infostealer Wallet-Material and Credential Exfiltration) and the field anchor for its trusted-platform content-channel delivery sub-shape (T4.013.001). It is worth contrasting carefully with the same-class siblings. Against T4.012 (clipper): a clipper needs the victim to transact and captures only that transfer's destination, whereas the Lumma/Vidar stealers here take the standing key material and session state off the endpoint — every wallet vault, wallet file, saved login, and session cookie present — so the attacker gains durable, independent control and realises value on its own schedule with no victim transaction required. Against T11.006 (seed at rest in third-party storage): T11.006's substrate is a cloud-backup or password-manager service compromised server-side; here the compromise is host-resident malware on the victim's own device. Against T15.003 / T15.004 (operator endpoint/credential): those scope enterprise hosts whose state controls a protocol or exchange signing surface, whereas this is the commodity consumer-endpoint shape — mass-distributed malware-as-a-service against individual wallet holders. The 2011 allInVain wallet.dat theft (see examples/2011-06-allinvain-first-major-bitcoin-theft.md) is the historical class anchor that was forced into T15 "broadly construed" for lack of this home.

The delivery innovation — and the part most worth tracking — is the abuse of a trusted first-party platform's user-generated-content channel. Wallpaper Engine's "application" wallpaper type is, by design, an executable that runs on the user's desktop; uploaded to Steam Workshop, it lets an attacker distribute arbitrary code under the trust users place in Steam community content, with auto-execution on apply and thousands–tens-of-thousands of installs per package. The password-protected-archive trick (password embedded in the filename or a bundled config) is a complementary evasion that defeats pre-extraction scanning. This shape is the natural companion to T4.012.002 (reputation-laundered fake-software distribution): both make a malicious download look legitimate, but where T4.012.002 manufactures a synthetic cross-platform reputation network, this rides a single, genuinely trusted platform's content feature. It also generalises across the 2025–2026 Steam-malware wave — the trojanised game Chemia (Prodaft, July 2025) and the FBI's 2026 investigation into PirateFi, BlockBlasters, and others — which is why OAK tracks T4.013.001 as a forward candidate pending consolidation of these anchors. Consistent with OAK's scoping of endpoint-malware incidents, the crypto-relevant primitive recorded here is the wallet-material/session harvesting; the surrounding general-malware facets — the RenEngine loader, DarkKomet backdoor, crypto miners, ransomware variants, and Python droppers — are delivery/operational context rather than separately-minted crypto-attack Techniques.

Techniques demonstrated (3)