Anime, manga, and games, with a take · A Yukimedia publication

← all stories games 2 sources · 1h ago ·

Steam Forums Hit by ClickFix Malware Campaign Disguised as Tech Support

The campaign exploits the trust users place in community troubleshooting on Steam forums, a vector that has received less attention than malware hidden in game files or mods.

Key Facts

  • Attackers use multiple Steam accounts to reply to forum threads about game crashes or bugs, offering fake troubleshooting steps.
  • The ClickFix tactic instructs users to open PowerShell with administrator privileges and paste a command that downloads and executes the XMRig cryptocurrency miner.
  • The miner is installed as a scheduled task named "XMRig-[computer name]" that runs at Windows startup with SYSTEM privileges.
  • BleepingComputer recommends users who suspect infection manually delete the scheduled task, remove the Defender exclusion for C:\Windows\Background, and delete that folder and its contents.
  • Game Spark warns that any forum post instructing a user to open cmd or PowerShell with administrator privileges is 100 percent malicious.

Reporting from 2 sources: Automaton, Game Spark.

Steam Forums Hit by ClickFix Malware Campaign Disguised as Tech Support

A widespread malware campaign is targeting Steam users through the platform's forums, using a social engineering tactic known as ClickFix. According to security site BleepingComputer, attackers create multiple Steam accounts and reply to threads where users report technical issues such as game crashes or bugs. The replies appear to offer helpful troubleshooting steps but instead direct users to open PowerShell with administrator privileges and paste a command. That command downloads and executes a cryptocurrency miner, specifically XMRig, which runs silently in the background using the infected PC's processing power. The script is disguised as a Windows optimization utility named "msf utility \ PC Opt." It creates a directory at C:\Windows\Background, adds it to Microsoft Defender's exclusion list, then downloads the miner from an external site as "system.txt" and renames it "system.exe." A scheduled task named "XMRig-[computer name]" is set to run the miner at Windows startup with SYSTEM privileges. BleepingComputer reports that the attackers are posting similar messages across forums for many different games, and users have already begun spreading warnings. The site recommends that anyone who suspects infection should scan with antivirus software, manually delete the scheduled task, remove the Defender exclusion, and delete the Background folder. Because other malicious actions beyond mining may have occurred, a full OS reinstall is also advised.

Attackers register multiple Steam accounts and reply to threads where users report technical issues such as game crashes or bugs. The replies appear to offer helpful troubleshooting steps but instead direct users to open PowerShell with administrator privileges and paste a command.

The PowerShell script is named "msf utility \ PC Opt" and is disguised as a Windows optimization utility. When executed, it displays fake messages indicating maintenance tasks such as deleting temporary files, updating drivers, checking disks, and scanning for malware. However, most of those tasks are not performed. The malicious processes are hidden in a function called "Advanced-Optimization."

The script creates the directory C:\Windows\Background and adds it to Microsoft Defender's exclusion list. It then downloads a cryptocurrency miner from an external site under the filename "system.txt" and renames it "system.exe." A scheduled task named "XMRig-[computer name]" is created to run the miner at Windows startup with SYSTEM privileges.

Game Spark notes that this attack method, called ClickFix, is not limited to Steam forums. It appears across various online tech support forums and via email. The outlet warns that any post instructing users to type "cmd" or "powershell" and run with administrator privileges is "100% a malware attack."

BleepingComputer recommends that users who suspect infection should scan with antivirus software, manually delete the scheduled task, remove the Defender exclusion, and delete the Background folder. Because other malicious actions beyond mining may have occurred, a full OS reinstall is also advised.

Synthesized by Yomimono from the 2 cited sources below, including Japanese-language reporting where cited, then editorially reviewed before publishing.

Sources