Steam discussion forums ClickFix campaign deploying XMRig miners
Campaign
Summary
Hide ▲
Show ▼
An ongoing ClickFix campaign on Steam discussion forums is tricking users into running PowerShell commands that install XMRig cryptominers. The operation abuses help threads about game crashes and other problems to gain execution on victim machines. It turns a seemingly helpful fix into a malware-delivery path that can persist across reboots.
Related Happenings
XMRig cryptominer delivered via Steam ClickFix PowerShell
Malware Activity
H score21
First: 26.07.2026 01:37
Last: 26.07.2026 01:37
Sources 1
How related:
However, when executing the command, it quietly downloads an XMRig miner executable and launches it on the computer.
About this happening:
A ClickFix lure on Steam discussion forums now turns fake troubleshooting replies into XMRig infections on Windows computers. Victims are told to run an administra...
XMRig cryptominer delivered via Steam ClickFix PowerShell
Malware ActivityHow related: However, when executing the command, it quietly downloads an XMRig miner executable and launches it on the computer.
About this happening: A ClickFix lure on Steam discussion forums now turns fake troubleshooting replies into XMRig infections on Windows computers. Victims are told to run an administra...
ClickLock ClickFix macOS targeting campaign
Campaign
H score33
First: 16.07.2026 15:33
Last: 16.07.2026 15:33
Sources 1
About this happening:
Group-IB reported a ClickLock macOS campaign that uses ClickFix paste-a-command lures and coercive app-killing loops to force victims to enter their system login...
ClickLock ClickFix macOS targeting campaign
CampaignAbout this happening: Group-IB reported a ClickLock macOS campaign that uses ClickFix paste-a-command lures and coercive app-killing loops to force victims to enter their system login...
ClickLock Stealer macOS forced-interaction infostealer activity
Malware Activity
H score27
First: 16.07.2026 15:33
Last: 16.07.2026 15:33
Sources 1
About this happening:
ClickLock Stealer is a macOS information-stealing malware that uses a ClickFix-style paste into Terminal and a fake system dialog to coerce users into entering the...
ClickLock Stealer macOS forced-interaction infostealer activity
Malware ActivityAbout this happening: ClickLock Stealer is a macOS information-stealing malware that uses a ClickFix-style paste into Terminal and a fake system dialog to coerce users into entering the...
Veil#Drop PureLog Stealer in-memory delivery operation
Malware Activity
H score30
First: 01.07.2026 17:30
Last: 01.07.2026 17:30
Sources 1
About this happening:
Veil#Drop is delivering PureLog Stealer through a fileless chain that keeps payloads entirely in memory, reducing disk artifacts and raising the chance of evading...
Veil#Drop PureLog Stealer in-memory delivery operation
Malware ActivityAbout this happening: Veil#Drop is delivering PureLog Stealer through a fileless chain that keeps payloads entirely in memory, reducing disk artifacts and raising the chance of evading...
KongTuke ClickFix and Teams access-seeking campaign
Campaign
H score33
First: 25.06.2026 11:54
Last: 25.06.2026 11:54
Sources 1
About this happening:
The KongTuke operation is using ClickFix lures and Microsoft Teams messages to widen access-seeking attacks against multiple organizations, increasing the risk of...
KongTuke ClickFix and Teams access-seeking campaign
CampaignAbout this happening: The KongTuke operation is using ClickFix lures and Microsoft Teams messages to widen access-seeking attacks against multiple organizations, increasing the risk of...
Timeline
-
25.07.2026 03:00 2 articles · 1d ago
Steam forum replies trick users into running PowerShell commands that install XMRig miners
Initial DisclosureThreat actors are abusing Steam discussion forum replies to target users posting about game crashes, lost inventory items, and other technical problems, instructing them to run PowerShell as administrator; the command downloads and launches an XMRig miner, masquerades as "msf utility \ PC Opt.", creates C:\Windows\Background, adds that path to Microsoft Defender exclusions, downloads payloads from msfconfig[.]icu, and creates an XMRig-[computer name] scheduled task for persistence.
Show sources
- Steam forum ClickFix attacks infect gamers with XMRig cryptominers — www.bleepingcomputer.com — 26.07.2026 01:37
- Steam forum ClickFix attacks infect gamers with XMRig cryptominers — www.bleepingcomputer.com — 26.07.2026 01:37