
In short
- Kaspersky discovered a malicious download of Wallpaper Engine on Steam Workshop and installed thousands of them.
- The malware stole Steam credentials, hijacked active sessions, and sent other payloads, including the Lumma and Vidar infostealers.
- The discovery follows a series of Steam-related crimes that have targeted gamers and crypto holders.
In report published on Monday, Kaspersky said criminals used the Steam Workshop to distribute malicious downloads of Wallpaper Engine that looked like cartoons, many with female characters.
“The image-based interface allows programs to run directly on a Windows computer, allowing attackers to secretly distribute malicious software if it is legitimate,” Kaspersky said, adding that it had identified many infected packages available through the Steam Workshop.
Kaspersky has also identified document images that share information about Lumma and Vidar, malware families widely used to steal credentials, browser credentials, and cryptocurrency wallet information, along with the RenEngine scanner. The researchers said the operation appears to be related to several threats rather than a single group.
“Many of these products were downloaded in the thousands or thousands,” the company said.
According to Kaspersky, the victims of the malware were in China and Russia, although the infection was also seen in Singapore, Hong Kong, Germany, Vietnam, India, and Canada.
Malicious videos can install malware directly or hide inside password-protected files released after installation, the company said, noting a 2025 scenario where the graphics card appears to launch legitimate computer games and secretly install them behind DarkKomet.
“Trusted platforms can be misused to spread malware: Attacks rely on users trusting the content of the environment,” Kaspersky researcher Maxim Starodubov said in a statement. “While many of the malware families are well-known, the delivery method enables the attackers to reach a large number of victims with seemingly innocuous actions.”
The findings add to a growing list of criminal activity related to Steam.
In July 2025, researchers with the cybersecurity company Prodaft reported that Steam Early Access games. Chemistry had been compromised to distribute Hijack Loader, Fickle Stealer, and Vidar Stealer malware targeting cryptocurrency wallets and user data. In March, the FBI announced search in a malware distributed across several Steam games, including Chemia, PirateFi, BlockBlasters, Dashverse, DashFPS, Lampy, Lunara, and Tokenova.
Daily Debrief A letter
Start each day with top stories right here, including originals, podcasts, videos and more.





