Steam Forum Help Threads Used to Deliver XMRig Cryptominers via PowerShell

steam-forum-users-hijacking-help-2005

Steam users are being targeted in a new wave of forum-based malware scams designed to trick players into installing cryptominers on their own PCs. The scheme, which piggybacks on ordinary “help” threads, uses a believable script that asks victims to run PowerShell with administrator privileges—quietly downloading and installing an XMRig cryptominer that then persists across reboots.

How the Steam “help thread” scam works

The attack follows a pattern: a bad actor posts about a broken install, crashing game, or another technical issue and then steers the conversation toward a “fix.” Instead of offering standard troubleshooting, the scammer tells the user to open PowerShell as an administrator and paste in a specific command.

That command installs the cryptominer payload in the background. The scam is set up so it requires both administrator privileges and user input, which is why the instructions are presented as a legitimate solution to a real-looking problem.

  • Victims are directed to run PowerShell as an admin.
  • The command quietly installs an XMRig executable.
  • It leverages a ClickFix-style approach, relying on believable prompts and a convincing troubleshooting flow.
  • It uses fake errors, verification prompts, and troubleshooting steps to reduce suspicion.

What the cryptominer does after installation

Cryptominers use a victim’s hardware to perform cryptocurrency “mining” calculations in the background, typically drawing on both CPU and GPU resources. The more capable the system, the more attempts the miner can make—meaning the attacker benefits from higher processing power without paying for hardware or electricity.

In this campaign, the setup is designed to maintain access:

  • It creates a temporary outbound rule in Windows Firewall to allow the miner download.
  • It moves the miner executable into a Windows background folder.
  • It launches automatically when the PC starts.

While antivirus scanning can sometimes detect known threats, the guidance in the report emphasizes that a full operating system reinstall is the safer option because users cannot be certain what else may have been installed during the initial compromise.

Why this matters for players (and what not to do)

This scam is effective because it blends into the Steam Forums’ everyday support culture. Players seeking answers may be more likely to follow instructions that appear to match their issue—especially when the “fix” includes realistic prompts and steps.

The core takeaway is simple: never run PowerShell commands provided by strangers in response to a forum post. Even if the command appears to “verify” files or “fix” a crashing game, it can be engineered to bypass protections and install persistent malware.

Extra context: other malware attempts and prevention steps

Cryptominer campaigns are part of a broader trend of bad-faith actors abusing Steam’s ecosystem, including malicious workshop content and trojan-style games. The report also notes that earlier incidents have affected titles and community spaces, including a recent case involving Meccha Chameleon that resulted in losing access to its official Discord server after investigating illicit-map claims.

On the platform side, Wallpaper Engine has disabled application wallpapers as a protective measure, stating that only a “very tiny number” of users were affected.