The gaming industry is often viewed as a sanctuary of entertainment, a digital playground where millions of users retreat to unwind. However, recent findings by cybersecurity researchers have shattered that illusion of safety, revealing a sophisticated and persistent campaign that has turned one of the most trusted community platforms—Steam Workshop—into a conduit for malicious software.
Security researchers at Kaspersky have uncovered a widespread campaign that has been operating since at least late 2025, specifically targeting users of Wallpaper Engine, a popular desktop customization application hosted on Valve’s Steam platform. By exploiting the inherent flexibility of the app, threat actors successfully distributed a variety of malicious payloads, ranging from credential-stealing infostealers to dangerous ransomware.
The Mechanism of Deception: A Trojan Horse in the Workshop
Steam Workshop is a cornerstone of the Steam experience. It allows developers and, more importantly, the community to create and share custom modifications, maps, and interface enhancements. For Wallpaper Engine users, the Workshop is a treasure trove of interactive, high-definition, and animated backgrounds that can breathe new life into a Windows desktop.
The vulnerability, however, lies in the very feature that makes the software so versatile: its support for "application wallpapers." Unlike a static JPEG or PNG file, these wallpapers can contain scripts, video files, and executable code designed to run within the Wallpaper Engine environment.
Hackers realized that they could disguise malicious software as harmless, high-quality, or trending wallpapers. These weaponized files were uploaded to the Workshop, often under the guise of popular gaming franchises, trending anime, or aesthetically pleasing landscapes to entice users into clicking "Subscribe."

Once a user subscribed to the wallpaper, it was automatically downloaded and, in many cases, the hidden malicious payload was executed. Kaspersky reports that these malicious files were frequently bundled within password-protected archives or hidden within seemingly benign directory structures. By the time the user realized anything was amiss, the malware had already established a foothold in their operating system.
Chronology of a Silent Campaign
The campaign appears to have been meticulously planned and executed. While the full extent of the operation is still being mapped, the timeline provided by security analysts suggests a multi-phase approach:
- Late 2025 (Initial Deployment): Threat actors began uploading the first batch of malicious wallpaper files to the Steam Workshop. These early iterations were likely tests to see how quickly they could bypass Steam’s automated moderation systems.
- Expansion Phase: Seeing that the content remained active for extended periods, the attackers scaled up their efforts. Dozens of unique, weaponized wallpapers were uploaded, each accumulating thousands of downloads.
- The Proliferation of Payloads: As the campaign matured, the variety of malware being delivered became increasingly sophisticated. What started as simple adware or cryptojackers evolved into dangerous infostealers like Lumma and Vidar, as well as botnet loaders.
- Detection and Remediation: In recent months, Kaspersky researchers identified the pattern and alerted the relevant authorities. Valve, the parent company of Steam, subsequently identified the malicious entries and purged them from the Workshop, though the cat-and-mouse game continues.
A Diverse Arsenal: What Was Being Distributed?
The diversity of the malware found in these wallpapers is particularly alarming. It suggests that the threat actors behind this campaign were not just looking for a quick payout, but were interested in long-term exploitation of victim machines.
- Infostealers (Lumma and Vidar): These are perhaps the most dangerous payloads identified. They are designed to silently scrape a user’s browser history, saved passwords, cryptocurrency wallet keys, and session cookies. This information is then exfiltrated to a command-and-control (C2) server, allowing the attackers to hijack entire online identities.
- Cryptocurrency Miners: These programs hijack the host’s GPU and CPU resources to mine digital assets for the attacker. While less overtly destructive than ransomware, they degrade system performance significantly and can lead to hardware damage due to sustained high temperatures.
- Botnet Loaders: By turning a user’s PC into a "zombie" machine, the attackers can add the computer to a larger network. This network can then be used for Distributed Denial of Service (DDoS) attacks, spam distribution, or further malware deployment.
- Ransomware and Backdoors: The presence of ransomware strains indicates that the attackers were willing to perform high-stakes extortion, locking users out of their personal files until a ransom is paid. Backdoors, meanwhile, allowed the attackers to retain persistent remote access, ensuring they could return to the infected machine at any time to deploy additional payloads.
Geographic Impact and Victimology
While the internet is borderless, this specific campaign showed a distinct concentration of victims. Data suggests that the primary impact was felt by users in Russia and China. Experts speculate that this may be due to the prevalence of specific gaming communities in those regions or perhaps a targeted effort by threat actors to exploit local trends in wallpaper customization.
However, it is crucial to note that no region is truly safe from such threats. Because Steam is a global platform, a malicious file uploaded from one corner of the world can be downloaded by a user in another in a matter of seconds. The "thousands or even tens of thousands" of downloads per item reported by Kaspersky highlight the sheer scale of the danger.

The Responsibility of Platforms vs. User Caution
The incident raises significant questions about the security responsibilities of digital distribution platforms. Valve provides the infrastructure for millions to share content, but the sheer volume of submissions makes real-time, deep-content moderation nearly impossible.
When asked about the situation, cybersecurity experts emphasize that while platforms like Steam must invest in better sandboxing and automated scanning, the responsibility also falls on the end-user.
"The fundamental issue here is trust," notes one security analyst. "Users see the Steam platform as a ‘walled garden’—a safe environment curated by a major corporation. That trust is being weaponized. Whether it’s a game, a mod, or a desktop wallpaper, users need to understand that anything executable is a potential threat."
Implications for the Future of Modding
This campaign is likely not the end, but rather a warning shot for the gaming community. As modding becomes more integral to the gaming experience, the platforms that facilitate it must evolve their security postures.
- Increased Scrutiny: We can expect platforms like Steam to implement more rigorous code-signing and behavior-analysis requirements for community-submitted content.
- User Awareness Campaigns: Education will become a primary defense. Platforms may begin to implement clearer warnings about the risks associated with third-party content.
- The Persistence of the Threat: The ease with which these hackers were able to re-upload content even after initial removals proves that the threat is persistent. As long as there is a financial incentive to compromise user accounts and steal data, hackers will continue to abuse the very features that make these platforms fun to use.
Conclusion: Staying Safe in a Connected World
For the average gamer, the takeaway is simple: exercise extreme caution when downloading community content. Even from trusted platforms like Steam, treat every download as a potential risk.

Users are encouraged to keep their antivirus software updated, run regular full-system scans, and avoid downloading content from creators with low reputations or suspiciously new accounts. If a wallpaper or mod asks for permissions that seem out of place—or if you notice sudden system sluggishness after installing a new add-on—it is time to act immediately.
The incident involving Wallpaper Engine serves as a stark reminder that in the digital age, our greatest tools for customization can, in the wrong hands, become the very instruments of our undoing. As we continue to blur the lines between our virtual and physical lives, our vigilance must remain as high as our enthusiasm for the platforms we love.





