Hackers are distributing malicious software through Wallpaper Engine packages hosted on the Steam Workshop. The threat involves attackers embedding hidden malware inside password-protected archives within these community-created wallpapers. Researchers identified dozens of compromised wallpapers that have accumulated tens of thousands of downloads each.
Researchers discover hidden malware in password-protected archives targeting Steam credentials and personal data across multiple regions.
Wallpaper Engine is a desktop application available through Steam that allows users to create and share animated wallpapers. The software includes functionality for running executable Windows applications directly from wallpaper packages. This feature creates a potential security vulnerability when users install untrusted community content.
Kaspersky researchers discovered the compromised wallpapers targeting users in multiple regions including China, Russia, Singapore, Hong Kong, Germany, and Canada. The malware primarily aims to steal Steam accounts and harvest user information. Attackers use password protection to conceal malicious archives within standard wallpaper packages.
The distribution method exploits Wallpaper Engine's capability to execute Windows applications from workshop content. Users who install compromised wallpapers risk exposing their Steam credentials and personal data to the embedded malware. Kaspersky identified multiple instances of this attack vector across different regions.
Source: PCGAMESN



