Kabaski indicated that the attackers were distributing malicious software using wallpaper content from Steam Creative Industries. Since this type of "appliable wallpaper" can run an enforceable program directly on Windows computers, the user may download a stealth program at the same time as it installs seemingly normal content.
We found dozens of infected wallpapers. Package
Kabaski stated that the researchers had identified dozens of wallpaper bags with malicious codes. The samples concerned two commonly stolen wooden horses, Lumma and Vidar, and the RenEngine loader.
These malicious programs are usually used to steal account documents, browser data and encrypt wallet information. According to researchers, this round is not a single-group exercise, more like multiple attackers who simultaneously use similar methods to throw malicious content.
Main victims are in China and Russia.
According to Kabaski, the victims are mainly in China and Russia, and cases of infection have also been reported in Singapore, Hong Kong, China, Germany, Viet Nam, India and Canada.
According to the company, the malicious wallpaper bag was dropped differently: Some are directly tied to wooden horses, others hide malicious documents in encrypted compressors and are then automatically released after installation.
Leveraging legitimate platforms to improve communication efficiency
Kabaski mentioned a similar case in 2025: a wallpaper would start a normal desktop game on the surface, but a DarkKomet backdoor program would be installed in secret.
According to researchers, such attacks depend on the confidence of users in the ecology of the formal platform. The attackers will have access to a large number of potential victims without having to pretend to be an independent downloading station and by packaging malicious content as a common creative workshop resource.
In July of this year, Cybersecurity also revealed that Steam's first experience game, Chemia, was used to spread Hijack Loader, Dickle Stealer and Vidar Stealer, with the same goal of encrypting wallets and user data. Earlier, in March, the FBI announced that it was investigating multiple malicious software disseminated through Steam games involving Chemia, PirateFi, Block Blasters, Dashverse, DashFPS, Lammy, Lunara and Tokenova.
