Steam Forums Used to Spread XMRig Cryptominer via Fake PowerShell Fix Commands
Cybercriminals are targeting PC gamers by posting fake technical solutions on Steam discussion forums, tricking users into running malicious PowerShell commands with administrator privileges. The attack, classified as a ClickFix campaign, disguises itself as a Windows optimization tool and displays convincing but fake system-repair progress messages to avoid suspicion. Once executed, the script disables TLS certificate validation, adds Microsoft Defender exclusions, and creates a Windows Firewall rule to communicate with the attacker-controlled domain msfconfig[.]icu. The malware then downloads the XMRig cryptocurrency miner, saves it as system.exe under C:\Windows\Background, and establishes persistence through a SYSTEM-privileged Windows Scheduled Task. Security researchers warn the technique could easily be replicated in enterprise environments where employees copy commands from forums or AI-generated responses.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in