Threat reportMalwareTL-2026-0827
Steam Workshop Abused to Distribute Malware via Wallpaper Engine (DarkKomet, Lumma, Vidar, RenEngine)
Steam Workshop Abused to Distribute Malware via Wallpaper (TL-2026-0827), also tracked as Malicious Steam Workshop Wallpapers, is a high-severity malware campaign, first published 2026-06-16. It has no confirmed attribution, affects Wallpaper Engine (Kristjan Skutta / Steam app 431960) Wallpaper Engine, maps to 26 MITRE ATT&CK techniques (T1005, T1027, T1036.005), and is covered by 9 detection rules and 36 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 26MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 36Indicators of compromise
Key facts for TL-2026-0827
- Threat ID
- TL-2026-0827
- Also known as
- Malicious Steam Workshop Wallpapers, Wallpaper Engine Workshop malware campaign
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution confidence
- NONE
- Motivation
- FINANCIAL
- Target sectors
- gaming, consumer, technology
- Target regions
- China, Russia, Singapore, Hong Kong, Germany, Vietnam, India, Canada
- Detection rules
- 9
- Indicators of compromise
- 36
Malware and tooling in Steam Workshop Abused to Distribute Malware via Wallpaper
Malware and tooling: DarkKomet, Lumma, RenEngine, Vidar
How Steam Workshop Abused to Distribute Malware via Wallpaper works
Multiple independent threat actors uploaded dozens of malicious 'application wallpapers' to the Steam Workshop, abusing Wallpaper Engine's ability to run executable content to deliver the DarkKomet backdoor, Lumma and Vidar infostealers, the RenEngine loader, crypto-miners and ransomware. Payloads ship inside the wallpaper package or in password-protected archives (password embedded in the filename or JSON config) and execute when the wallpaper is applied. One chain dropped Synaptics.exe (DarkKomet) plus a trojanized AggregatorHost.dll to steal Steam credentials.
In June 2026 Kaspersky (Securelist) disclosed an ongoing abuse campaign in which threat actors weaponize the Steam Workshop content-sharing platform to distribute malware through Wallpaper Engine, a popular Windows live-wallpaper application (Steam app 431960). Wallpaper Engine supports an 'application wallpaper' type that can run bundled executables, DLLs and scripts on the host with the privileges of the user — by design it permits arbitrary code execution, which the attackers abuse as their initial-access primitive.
The actors upload wallpaper packages whose archives contain malicious executables, DLLs and Python scripts directly, or hide the payload inside a password-protected archive where the password is embedded in the filename or in the wallpaper's JSON configuration so it can be extracted and executed automatically without user interaction. When a victim subscribes to and applies the wallpaper, the bundled payload runs. In one analyzed chain the launcher '._cache_GAME1.exe' opened a legitimate-looking game (the 'NTRaholic' wallpaper launched a real game to reduce suspicion) while simultaneously installing a DarkKomet backdoor dropped as 'Synaptics.exe'. A custom/trojanized 'AggregatorHost.dll' was deployed to locate Steam accounts on the machine and exfiltrate the stored credentials to the attacker C2 (e.g. http://120.48.156.17/ey.php), enabling session/account takeover and follow-on malware delivery.
Kaspersky observed dozens of malicious wallpapers, many already downloaded thousands to tens of thousands of times, active since at least late 2025, with a sample analyzed in December 2025. Telemetry shows download attempts heavily concentrated in China (~89%) and Russia (~5.5%), with smaller shares in Singapore, Hong Kong, Germany, Vietnam, India and Canada. Kaspersky assesses the activity as the work of multiple independent threat actors rather than a single coordinated group, motivated chiefly by gaming-account theft, infostealer data collection, cryptomining and ransomware deployment. By publication Steam had removed the identified items, but new malicious wallpapers continue to appear, making this a recurring supply-chain-style abuse of a trusted distribution platform. Kaspersky verdicts for the samples include HEUR:Backdoor.Win32.DarkKomet, HEUR:Trojan-PSW.Win32.gen, HEUR:Trojan-PSW.Win32.Python.gen, Trojan-Dropper.Python.Agent, HEUR:Trojan-Ransom.Win32.Gen.gen and PDM:Trojan.Win32.Generic.
MITRE ATT&CK techniques used in TL-2026-0827
Collection
Defense Evasion
T1027 Obfuscated Files or Information; T1036.005 Match Legitimate Resource Name or Location; T1140 Deobfuscate/Decode Files or Information; T1574.001 DLL
Exfiltration
T1041 Exfiltration Over C2 Channel
Execution
T1059.006 Command and Scripting Interpreter: Python; T1106 Native API; T1204.002 User Execution: Malicious File
Command and Control
T1071.001 Application Layer Protocol: Web Protocols; T1102.002 Web Service: Bidirectional Communication; T1105 Ingress Tool Transfer
Discovery
T1083 File and Directory Discovery; T1518 Software Discovery
Initial Access
T1189 Drive-by Compromise; T1195 Supply Chain Compromise
Impact
T1486 Data Encrypted for Impact; T1496 Resource Hijacking
Credential Access
T1528 Steal Application Access Token; T1539 Steal Web Session Cookie; T1555 Credentials from Password Stores
Persistence
T1547.001 Registry Run Keys / Startup Folder
stealth
T1574.001 Hijack Execution Flow: DLL
Resource Development
T1583 Acquire Infrastructure; T1583.006 Acquire Infrastructure: Web Services; T1587.001 Develop Capabilities: Malware; T1608.001 Stage Capabilities: Upload Malware
Affected products and versions in Steam Workshop Abused to Distribute Malware via Wallpaper
- Wallpaper Engine (Kristjan Skutta / Steam app 431960) — Wallpaper Engine
Vulnerable versions: Application/executable wallpaper feature (all current versions) - Valve — Steam Workshop
Vulnerable versions: User-generated content distribution (platform abuse)
Remediation for Steam Workshop Abused to Distribute Malware via Wallpaper
Immediate actions
- Block the C2 indicators 202.144.192.29, 120.48.156.17 and brightly.to at the perimeter/DNS and proxy
- Hunt for and remove Synaptics.exe, ._cache_GAME1.exe and a non-system AggregatorHost.dll outside %WINDIR%\System32
- Unsubscribe from and delete any of the listed malicious Steam Workshop wallpaper IDs; treat any executable-type ('application') wallpaper as untrusted
- Force-reset Steam credentials and revoke active Steam sessions for any host that ran an affected wallpaper; enable Steam Guard/MFA
Workarounds
- In Wallpaper Engine, disable or avoid 'application' type wallpapers and content from unknown publishers
- Run gaming/Wallpaper Engine on non-privileged accounts segmented from credential stores
Longer-term hardening
- Deploy EDR with behavioral detection for child-process execution spawned by the Wallpaper Engine process (wallpaper32/wallpaper64)
- Restrict or prohibit Wallpaper Engine application/executable wallpapers via policy on managed endpoints
- Educate users that Steam Workshop content is user-generated and can run code; only install scene/video/web wallpapers from trusted authors
Weaknesses (CWE) in Steam Workshop Abused to Distribute Malware via Wallpaper
Timeline of Steam Workshop Abused to Distribute Malware via Wallpaper
- Threat actors begin abusing the Steam Workshop to distribute malware via Wallpaper Engine 'application' wallpapers (active since at least late 2025 per Kaspersky).
- Kaspersky analyzes a malicious wallpaper sample in December 2025, identifying the 'application' (executable) wallpaper type as the initial-access primitive that allows bundled code to run on the host when the wallpaper is applied.
- Launcher ._cache_GAME1.exe observed opening a decoy/legitimate game (the 'NTRaholic' wallpaper launches a real game to reduce suspicion) while simultaneously installing the DarkKomet backdoor dropped as Synaptics.exe.
- Payloads observed bundled directly in the wallpaper archive or hidden in password-protected archives where the password is embedded in the filename or the wallpaper's JSON configuration, allowing automatic extraction and execution without user interaction; second-stage archives (Themes2.zip) staged from attacker infrastructure and abused cloud services (Dropbox, Google Docs/Drive).
- Trojanized AggregatorHost.dll observed searching for Steam accounts and exfiltrating stored credentials to C2 at http://120.48.156.17/ey.php, enabling gaming-account takeover.
- Dozens of malicious wallpaper packages identified, several already downloaded thousands to tens of thousands of times; Kaspersky verdicts span DarkKomet, Lumma, Vidar, the RenEngine loader, Python password-stealer droppers, cryptominers and ransomware.
- Kaspersky assesses the activity as the work of multiple independent, financially motivated threat actors (gaming-account theft, infostealer collection, cryptomining, ransomware) rather than a single coordinated group.
- Download-attempt telemetry shows heavy concentration in China (~89%) and Russia (~5.5%), with smaller shares across Singapore, Hong Kong, Germany, Vietnam, India and Canada.
- Kaspersky notes new infected wallpapers continue to appear on the Steam Workshop after removal, making this a recurring supply-chain-style abuse of a trusted distribution platform.
- By publication Steam had removed the identified malicious wallpapers and links from the Workshop.
- Kaspersky/Securelist publicly disclose the campaign ('Gamers beware: dozens of malicious wallpapers found on Steam Workshop'); the Kaspersky press release and BleepingComputer report it the same day.
Sources cited for Steam Workshop Abused to Distribute Malware via Wallpaper
- Gamers beware: dozens of malicious wallpapers found on Steam Workshop
- Kaspersky discovered a malware campaign targeting Steam users through infected wallpaper
- Steam Workshop abused to spread malware via Wallpaper Engine app
- Malpedia: DarkComet (DarkKomet) RAT
- Malpedia: Lumma Stealer (LummaC2)
- Malpedia: Vidar Stealer
- MITRE ATT&CK T1195 Supply Chain Compromise
Detection coverage for TL-2026-0827
As of 2026-06-16, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0827 across Splunk SPL, Microsoft KQL and Sigma, covering 36 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.