EGW-NewsSteam-hjälptrådar används för att plantera kryptominers
Steam-hjälptrådar används för att plantera kryptominers
113
Add as a Preferred Source
0
0

Steam-hjälptrådar används för att plantera kryptominers

Denna artikel finns tillgänglig på följande språk

The Steam discussion boards are where people go when a game will not launch, and that is exactly why attackers have moved in. Bad actors are answering help threads with fake fixes that end up installing a cryptocurrency miner on the machine, a campaign first reported by Bleeping Computer.

The setup is ordinary enough to work. Someone posts about a crash, a broken install or missing in-game items. A reply arrives telling them to open PowerShell as an administrator and paste in a command, framed as the fix. Because the victim types it themselves, the download slips past the checks that would normally stop a malicious executable dead. The technique has a name, ClickFix, and it works by arriving as help rather than as an attachment.

I have spent this year learning to build things by pasting commands I only half understand into a terminal, which is the exact habit this attack is designed to harvest. The thread is real. The person asking for help is real. Only the answer is poisoned.

Steam Help Threads Are Being Used to Plant Cryptominers 1

Image Credit: BleepingComputer

What runs is dressed up as maintenance. The script announces itself as a Windows optimisation utility and produces a stream of fake progress messages about updating drivers, defragmenting data and emptying the recycle bin, none of which it is doing, with the messages timed to appear at random intervals between roughly 1.5 and 8 seconds so the process looks alive. Run it without administrator rights and it displays an error saying it needs them, then closes. That refusal is the whole point of the instruction to elevate.

With administrator rights, the script gets to work. It disables TLS certificate validation, creates a directory inside the Windows folder that it adds to Microsoft Defender's exclusion list, tells Windows Firewall to allow traffic to an external domain reported as msfconfigicu, and pulls down an XMRig miner. It then registers a scheduled task named after the machine so the miner starts with Windows every time. From then on the computer is quietly working for somebody else, and the software has proven difficult to remove.

The recovery advice is blunt. If you find that scheduled task, or a folder in Windows carrying a Defender exception you did not create, reinstalling the operating system is the safer response, because there is no way to know what else the script pulled in while it had administrator access. Anyone who ran the command should treat saved passwords and session tokens as compromised rather than assume the miner was the only payload.

This particular script is Windows-only, but the behaviour it exploits is more normalised elsewhere. Running scripts copied off the internet is a routine part of getting games working on Linux, which makes anyone new to that side of PC gaming a softer target for the same social approach. The defence is the same in both places and it is unglamorous: do not run commands handed to you by a stranger, however confident the stranger sounds.

Steam has been dealing with the store-side version of this problem all year. A malware game on Steam earlier this summer, a request-only early access title called Chemia, was found shipping Fickle Stealer and HijackLoader alongside itself, with researchers at Prodaft tying it to a group tracked as Larva-208 and pointing at a file added to the build on 22 July that pulled in further payloads.

"When users download and launch the game, the malware executes alongside the legitimate application"

— Prodaft

Chemia was the third known incident inside six months. PirateFi went up as a free-to-play title and was promoted on Telegram with bot messages and fake moderator job offers. Sniper: Phantom's Resolution never carried malware in its Steam build at all, because a scammer registered the domain the real developers had listed but not yet bought, and served a fake demo from it. Separately, the FBI identified five infected Steam games used to take at least $220,000 from players. Each attempt used a different door: internal upload, external link, poisoned update, and now the forums, which have no submission review to pass in the first place. I know two of those three store cases were surfaced by outside researchers and users rather than by Valve, which says something about where the checking actually happens.

Steam Help Threads Are Being Used to Plant Cryptominers 2

None of this is unique to Valve. PlayStation was hit by a wave of account hacks in May 2026, and crypto-flavoured takeovers have repeatedly landed on YouTube channels and on corporate accounts, including Stellar Blade's in July 2025. The scale explains the attention. Steam posted its best half-year on record in the first six months of 2026, an estimated $11.1 billion according to Alinea Analytics, helped by higher prices on new releases and publishers bringing games back after retiring their own launchers. Half of all Steam accounts belonged to Chinese-speaking users by early 2025, a floor that holds up the platform between releases.

"Zoom out over the last decade and things get really crazy"

— Rhys Elliott

A store that size is a standing target, and the parts of it that attract attackers are the parts that are not really a store. Over 90% of Steam users read reviews before buying, with 40% doing it every time, and a Mixed rating puts off more than half of them. The community layer is the purchase funnel, which is what makes it valuable to Valve and valuable to whoever wants to reach a few thousand people having a bad day with their PC. I think the store incidents point at review gaps that Valve can close with better checks, while the forum attack points at a layer where no check exists at all, because a reply in a thread is not something anyone submits for approval.

That layer is now being copied. Epic Games Store is rebuilding its launcher with written player reviews, player profiles, product detail pages and patch notes on store pages, alongside claims of a cold start five times faster than the current app. Those are the features that make Steam sticky, and they arrive attached to the same problem, since a storefront with community replies inherits a place for strangers to offer fixes.

Valve has spent the year improving the parts of Steam people asked about, including a gifting overhaul that lets players send games to friends without accounts and across regions with pricing adjusted to the recipient. Every feature that widens the platform also widens what sits around it. For now the practical steps are small. Treat any forum reply that asks for administrator rights as hostile by default, check Task Scheduler and the Windows directory if you have already run something you regret, and remember that the fake utility's entire job is to look busy while it works. The people running this are not breaking Steam. They are using it exactly as designed, and answering a question nobody else bothered to answer.

Missa inte esportnyheter och uppdatering! Registrera dig och få veckovisa artiklar!
Registrera dig

Read also, Ukrainian police in Lviv Oblast detained a group accused of stealing more than 600,000 Roblox accounts between October 2025 and January 2026 and reselling them on Russian forums for close to 10 million hryvnia, roughly $240,000 to $250,000. Investigators say the three suspects, aged 19, 21 and 22, used stolen cookie files and credential-stealing malware distributed as cheats and free Robux generators, which is the same trick as the Steam campaign aimed at a younger audience.

Lämna en kommentar
Gillade du artikeln?
0
0

Kommentarer

FREE SUBSCRIPTION ON EXCLUSIVE CONTENT
Receive a selection of the most important and up-to-date news in the industry.
*
*Only important news, no spam.
SUBSCRIBE
LATER