{"rewrite":{"id":"r_d52ce176f0474866fac91b13","clusterId":"c_ffe6c3d61d6cdfb1a660409f","slug":"steam-forums-hit-by-clickfix-malware-campaign-disguised-as-tech-support","model":"deepseek-v4-flash:free","headline":"Steam Forums Hit by ClickFix Malware Campaign Disguised as Tech Support","summary":"A widespread malware campaign is targeting Steam users through the platform's forums, using a social engineering tactic known as ClickFix. According to security site BleepingComputer, attackers create multiple Steam accounts and reply to threads where users report technical issues such as game crashes or bugs. The replies appear to offer helpful troubleshooting steps but instead direct users to open PowerShell with administrator privileges and paste a command. That command downloads and executes a cryptocurrency miner, specifically XMRig, which runs silently in the background using the infected PC's processing power. The script is disguised as a Windows optimization utility named \"msf utility \\ PC Opt.\" It creates a directory at C:\\Windows\\Background, adds it to Microsoft Defender's exclusion list, then downloads the miner from an external site as \"system.txt\" and renames it \"system.exe.\" A scheduled task named \"XMRig-[computer name]\" is set to run the miner at Windows startup with SYSTEM privileges. BleepingComputer reports that the attackers are posting similar messages across forums for many different games, and users have already begun spreading warnings. The site recommends that anyone who suspects infection should scan with antivirus software, manually delete the scheduled task, remove the Defender exclusion, and delete the Background folder. Because other malicious actions beyond mining may have occurred, a full OS reinstall is also advised.","whyItMatters":"The campaign exploits the trust users place in community troubleshooting on Steam forums, a vector that has received less attention than malware hidden in game files or mods.","webCardHtml":"\u003cp\u003eAttackers register multiple Steam accounts and reply to threads where users report technical issues such as game crashes or bugs. The replies appear to offer helpful troubleshooting steps but instead direct users to open PowerShell with administrator privileges and paste a command.\u003c/p\u003e\u003cp\u003eThe PowerShell script is named \u0026#34;msf utility \\ PC Opt\u0026#34; and is disguised as a Windows optimization utility. When executed, it displays fake messages indicating maintenance tasks such as deleting temporary files, updating drivers, checking disks, and scanning for malware. However, most of those tasks are not performed. The malicious processes are hidden in a function called \u0026#34;Advanced-Optimization.\u0026#34;\u003c/p\u003e\u003cp\u003eThe script creates the directory C:\\Windows\\Background and adds it to Microsoft Defender\u0026#39;s exclusion list. It then downloads a cryptocurrency miner from an external site under the filename \u0026#34;system.txt\u0026#34; and renames it \u0026#34;system.exe.\u0026#34; A scheduled task named \u0026#34;XMRig-[computer name]\u0026#34; is created to run the miner at Windows startup with SYSTEM privileges.\u003c/p\u003e\u003cp\u003eGame Spark notes that this attack method, called ClickFix, is not limited to Steam forums. It appears across various online tech support forums and via email. The outlet warns that any post instructing users to type \u0026#34;cmd\u0026#34; or \u0026#34;powershell\u0026#34; and run with administrator privileges is \u0026#34;100% a malware attack.\u0026#34;\u003c/p\u003e\u003cp\u003eBleepingComputer recommends that users who suspect infection should scan with antivirus software, manually delete the scheduled task, remove the Defender exclusion, and delete the Background folder. Because other malicious actions beyond mining may have occurred, a full OS reinstall is also advised.\u003c/p\u003e","blueskyPost":"Steam forums are being used to spread malware via fake tech support replies. Attackers pose as helpful users, tricking victims into running PowerShell commands that install a cryptocurrency miner. BleepingComputer reports the campaign is widespread across multiple game forums.","twitterPost":"If someone on a Steam forum tells you to open PowerShell as admin to fix a crash, do not do it. BleepingComputer reports a ClickFix campaign is installing XMRig miners that way. The script even adds itself to Defender's exclusion list.","threadsPost":null,"newsletterBlurb":"A malware campaign on Steam forums uses fake tech support replies to trick users into installing a cryptocurrency miner. Attackers pose as helpful community members and direct victims to run PowerShell commands with administrator privileges. Security site BleepingComputer reports the scheme is active across forums for many different games.","attributionJson":"[{\"source\":\"Automaton\",\"url\":\"https://automaton-media.com/articles/newsjp/20260727-456839/\",\"title\":\"Malicious messages directing users to malware infections rampant on Steam forums: A deceptive tactic disguised as friendly advice\"},{\"source\":\"Game Spark\",\"url\":\"http://www.gamespark.jp/article/2026/07/27/169792.html\",\"title\":\"マルウェア侵入先は怪しいゲームやModだけじゃない！Steam掲示板にもマルウェア導入手順が仕込まれていることがあると海外メディアが注意喚起\"}]","lintFlagsJson":null,"lintHits":0,"costUsd":0,"inputTokens":13034,"outputTokens":1455,"status":"published","repairAttempts":0,"nextRepairAt":null,"factsAttemptedAt":1785141705,"createdAt":"2026-07-27T08:33:46.000Z","publishedAt":"2026-07-27T08:35:45.000Z","updatedAt":"2026-07-27T08:33:46.000Z"},"cluster":{"id":"c_ffe6c3d61d6cdfb1a660409f","canonicalTitle":"Steamのフォーラムにて、「マルウェア感染に仕向ける」悪質メッセージ多発中。“親切アドバイスのフリ”をした誘導手口","representativeArticleId":"a_5495c69f939fa402832a7602","sourceCount":2,"writtenSourceCount":2,"writeAttempts":0,"isSolo":false,"entitiesJson":"{\"anime_titles\":[],\"manga_titles\":[],\"work_titles\":[],\"studios\":[],\"people\":[],\"type\":\"news\",\"domain\":\"games\",\"is_roundup\":false}","contentType":"news","status":"published","firstSeenAt":"2026-07-27T04:14:32.000Z","lastSeenAt":"2026-07-27T07:45:03.000Z","updatedAt":"2026-07-27T08:35:45.000Z"},"attribution":[{"source":"Automaton","url":"https://automaton-media.com/articles/newsjp/20260727-456839/","title":"Steamのフォーラムにて、「マルウェア感染に仕向ける」悪質メッセージ多発中。“親切アドバイスのフリ”をした誘導手口"},{"source":"Game Spark","url":"http://www.gamespark.jp/article/2026/07/27/169792.html","title":"マルウェア侵入先は怪しいゲームやModだけじゃない！Steam掲示板にもマルウェア導入手順が仕込まれていることがあると海外メディアが注意喚起"}],"entities":{"anime_titles":[],"manga_titles":[],"work_titles":[],"studios":[],"people":[],"type":"news","domain":"games","is_roundup":false},"keyFacts":["Attackers use multiple Steam accounts to reply to forum threads about game crashes or bugs, offering fake troubleshooting steps.","The ClickFix tactic instructs users to open PowerShell with administrator privileges and paste a command that downloads and executes the XMRig cryptocurrency miner.","The miner is installed as a scheduled task named \"XMRig-[computer name]\" that runs at Windows startup with SYSTEM privileges.","BleepingComputer recommends users who suspect infection manually delete the scheduled task, remove the Defender exclusion for C:\\Windows\\Background, and delete that folder and its contents.","Game Spark warns that any forum post instructing a user to open cmd or PowerShell with administrator privileges is 100 percent malicious."]}
