# Steam Workshop Abused to Distribute Malware via Wallpaper Engine (DarkKomet, Lumma, Vidar, RenEngine)

> Multiple independent threat actors uploaded dozens of malicious 'application wallpapers' to the Steam Workshop, abusing Wallpaper Engine's ability to run executable content to deliver the DarkKomet backdoor, Lumma and Vidar infostealers, the RenEngine loader, crypto-miners and ransomware. Payloads ship inside the wallpaper package or in password-protected archives (password embedded in the filename or JSON config) and execute when the wallpaper is applied. One chain dropped Synaptics.exe (DarkKomet) plus a trojanized AggregatorHost.dll to steal Steam credentials.

- **Published:** 2026-06-16T00:00:00Z
- **Last reviewed:** 2026-06-16T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0827
- **ID:** TL-2026-0827
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 36 (full data via the Threadlinqs MCP server — Purple tier)

## Description

In June 2026 Kaspersky (Securelist) disclosed an ongoing abuse campaign in which threat actors weaponize the Steam Workshop content-sharing platform to distribute malware through Wallpaper Engine, a popular Windows live-wallpaper application (Steam app 431960). Wallpaper Engine supports an 'application wallpaper' type that can run bundled executables, DLLs and scripts on the host with the privileges of the user — by design it permits arbitrary code execution, which the attackers abuse as their initial-access primitive.

The actors upload wallpaper packages whose archives contain malicious executables, DLLs and Python scripts directly, or hide the payload inside a password-protected archive where the password is embedded in the filename or in the wallpaper's JSON configuration so it can be extracted and executed automatically without user interaction. When a victim subscribes to and applies the wallpaper, the bundled payload runs. In one analyzed chain the launcher '._cache_GAME1.exe' opened a legitimate-looking game (the 'NTRaholic' wallpaper launched a real game to reduce suspicion) while simultaneously installing a DarkKomet backdoor dropped as 'Synaptics.exe'. A custom/trojanized 'AggregatorHost.dll' was deployed to locate Steam accounts on the machine and exfiltrate the stored credentials to the attacker C2 (e.g. http://120.48.156.17/ey.php), enabling session/account takeover and follow-on malware delivery.

Kaspersky observed dozens of malicious wallpapers, many already downloaded thousands to tens of thousands of times, active since at least late 2025, with a sample analyzed in December 2025. Telemetry shows download attempts heavily concentrated in China (~89%) and Russia (~5.5%), with smaller shares in Singapore, Hong Kong, Germany, Vietnam, India and Canada. Kaspersky assesses the activity as the work of multiple independent threat actors rather than a single coordinated group, motivated chiefly by gaming-account theft, infostealer data collection, cryptomining and ransomware deployment. By publication Steam had removed the identified items, but new malicious wallpapers continue to appear, making this a recurring supply-chain-style abuse of a trusted distribution platform. Kaspersky verdicts for the samples include HEUR:Backdoor.Win32.DarkKomet, HEUR:Trojan-PSW.Win32.gen, HEUR:Trojan-PSW.Win32.Python.gen, Trojan-Dropper.Python.Agent, HEUR:Trojan-Ransom.Win32.Gen.gen and PDM:Trojan.Win32.Generic.

## MITRE ATT&CK

- T1583 Acquire Infrastructure
- T1583.006 Acquire Infrastructure: Web Services
- T1608.001 Stage Capabilities: Upload Malware
- T1587.001 Develop Capabilities: Malware
- T1195 Supply Chain Compromise
- T1189 Drive-by Compromise
- T1204.002 User Execution: Malicious File
- T1059.006 Command and Scripting Interpreter: Python
- T1106 Native API
- T1547.001 Registry Run Keys / Startup Folder
- T1574.001 Hijack Execution Flow: DLL
- T1036.005 Match Legitimate Resource Name or Location
- T1027 Obfuscated Files or Information
- T1140 Deobfuscate/Decode Files or Information
- T1574.001 DLL
- T1555 Credentials from Password Stores
- T1528 Steal Application Access Token
- T1539 Steal Web Session Cookie
- T1083 File and Directory Discovery
- T1518 Software Discovery
- T1005 Data from Local System
- T1071.001 Application Layer Protocol: Web Protocols
- T1105 Ingress Tool Transfer
- T1102.002 Web Service: Bidirectional Communication
- T1041 Exfiltration Over C2 Channel
- T1486 Data Encrypted for Impact
- T1496 Resource Hijacking

## Sources

- [Gamers beware: dozens of malicious wallpapers found on Steam Workshop](https://securelist.com/dozens-of-malicious-wallpapers-found-on-steam-workshop/120186/)
- [Kaspersky discovered a malware campaign targeting Steam users through infected wallpaper](https://www.kaspersky.com/about/press-releases/kaspersky-discovered-a-malware-campaign-targeting-steam-users-through-infected-wallpaper)
- [Steam Workshop abused to spread malware via Wallpaper Engine app](https://www.bleepingcomputer.com/news/security/steam-workshop-abused-to-spread-malware-via-wallpaper-engine-app/)
- [Malpedia: DarkComet (DarkKomet) RAT](https://malpedia.caad.fkie.fraunhofer.de/details/win.darkcomet)
- [Malpedia: Lumma Stealer (LummaC2)](https://malpedia.caad.fkie.fraunhofer.de/details/win.lumma)
- [Malpedia: Vidar Stealer](https://malpedia.caad.fkie.fraunhofer.de/details/win.vidar)
- [MITRE ATT&CK T1195 Supply Chain Compromise](https://attack.mitre.org/techniques/T1195/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0827
