Find notable cyber news and cases, enriched with sources, timelines, and signals.

Steam discussion forums ClickFix campaign deploying XMRig miners

Campaign
First reported
Last updated
Happening score
H score 34
1 unique sources, 1 articles

Summary

Hide ▲

An ongoing ClickFix campaign on Steam discussion forums is tricking users into running PowerShell commands that install XMRig cryptominers. The operation abuses help threads about game crashes and other problems to gain execution on victim machines. It turns a seemingly helpful fix into a malware-delivery path that can persist across reboots.

Related Happenings

XMRig cryptominer delivered via Steam ClickFix PowerShell

Malware Activity
H score21 First: 26.07.2026 01:37 Last: 26.07.2026 01:37 Sources 1

How related: However, when executing the command, it quietly downloads an XMRig miner executable and launches it on the computer.

About this happening: A ClickFix lure on Steam discussion forums now turns fake troubleshooting replies into XMRig infections on Windows computers. Victims are told to run an administra...

ClickLock ClickFix macOS targeting campaign

Campaign
H score33 First: 16.07.2026 15:33 Last: 16.07.2026 15:33 Sources 1

About this happening: Group-IB reported a ClickLock macOS campaign that uses ClickFix paste-a-command lures and coercive app-killing loops to force victims to enter their system login...

ClickLock Stealer macOS forced-interaction infostealer activity

Malware Activity
H score27 First: 16.07.2026 15:33 Last: 16.07.2026 15:33 Sources 1

About this happening: ClickLock Stealer is a macOS information-stealing malware that uses a ClickFix-style paste into Terminal and a fake system dialog to coerce users into entering the...

Veil#Drop PureLog Stealer in-memory delivery operation

Malware Activity
H score30 First: 01.07.2026 17:30 Last: 01.07.2026 17:30 Sources 1

About this happening: Veil#Drop is delivering PureLog Stealer through a fileless chain that keeps payloads entirely in memory, reducing disk artifacts and raising the chance of evading...

KongTuke ClickFix and Teams access-seeking campaign

Campaign
H score33 First: 25.06.2026 11:54 Last: 25.06.2026 11:54 Sources 1

About this happening: The KongTuke operation is using ClickFix lures and Microsoft Teams messages to widen access-seeking attacks against multiple organizations, increasing the risk of...

Timeline

  1. 25.07.2026 03:00 2 articles · 1d ago

    Steam forum replies trick users into running PowerShell commands that install XMRig miners

    Initial Disclosure

    Threat actors are abusing Steam discussion forum replies to target users posting about game crashes, lost inventory items, and other technical problems, instructing them to run PowerShell as administrator; the command downloads and launches an XMRig miner, masquerades as "msf utility \ PC Opt.", creates C:\Windows\Background, adds that path to Microsoft Defender exclusions, downloads payloads from msfconfig[.]icu, and creates an XMRig-[computer name] scheduled task for persistence.

    Show sources