The record
Written from the 1 report below. Nothing here is unsourced.
- Threat actors are posting replies on Steam discussion forums offering fake fixes for game crashes and other technical problems, tricking users into running PowerShell commands as administrators.
- The commands download a disguised Windows optimization tool that actually installs an XMRig cryptominer, adds a Microsoft Defender exclusion for its folder, and sets up a scheduled task to run at startup with SYSTEM privileges.
- Because victims run the commands manually, the attacks can bypass some automated security protections.
- Users should never run PowerShell commands from strangers in forums, and those infected should look for the 'C:\Windows\Background' directory and an 'XMRig-' scheduled task, then scan and clean their systems.
What to watch next
- Whether Steam takes action to curb these fake 'fix' replies on its discussion forums
- Whether the campaign expands to other game or community forums beyond Steam
- Clarification on whether the script's cleanup of existing XMRig files targets rival miners or earlier versions of itself
Coverage1
1 report
International1
All filed from United States
Named United States · Microsoft · PowerShell · Steam · XMRig
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
