XMRig cryptominer delivered via Steam ClickFix PowerShell
Malware Activity
Summary
Hide ▲
Show ▼
A ClickFix lure on Steam discussion forums now turns fake troubleshooting replies into XMRig infections on Windows computers. Victims are told to run an administrator PowerShell command, and the command quietly downloads the miner from msfconfig[.]icu and launches it locally. The payload also creates a Microsoft Defender exclusion and sets up startup persistence, increasing the chance the miner stays active.
Related Happenings
Steam discussion forums ClickFix campaign deploying XMRig miners
Campaign
H score34
First: 26.07.2026 01:37
Last: 26.07.2026 01:37
Sources 1
How related:
Steam discussion forums are being abused in ClickFix attacks that pretend to be fixes for game and computer problems but actually infect devices with cryptominers.
About this happening:
An ongoing ClickFix campaign on Steam discussion forums is tricking users into running PowerShell commands that install XMRig cryptominers. The operation abuses he...
Steam discussion forums ClickFix campaign deploying XMRig miners
CampaignHow related: Steam discussion forums are being abused in ClickFix attacks that pretend to be fixes for game and computer problems but actually infect devices with cryptominers.
About this happening: An ongoing ClickFix campaign on Steam discussion forums is tricking users into running PowerShell commands that install XMRig cryptominers. The operation abuses he...
GPU cryptomining malware using ScreenConnect and SEO poisoning
Malware Activity
H score16
First: 28.05.2026 00:31
Last: 28.05.2026 00:31
Sources 1
About this happening:
A cryptojacking malware operation is spreading through SEO-poisoned download pages and, in some cases, AI chatbot recommendations, putting high-performance Windows s...
GPU cryptomining malware using ScreenConnect and SEO poisoning
Malware ActivityAbout this happening: A cryptojacking malware operation is spreading through SEO-poisoned download pages and, in some cases, AI chatbot recommendations, putting high-performance Windows s...
Fake Gemini CLI and Claude Code SEO-poisoning infostealer campaign
Campaign
H score33
First: 22.05.2026 14:30
Last: 22.05.2026 14:30
Sources 1
About this happening:
Cyber threat actors ran a malicious SEO-poisoning campaign that impersonated Google Gemini CLI and Anthropic Claude Code to push malicious downloads. The operation...
Fake Gemini CLI and Claude Code SEO-poisoning infostealer campaign
CampaignAbout this happening: Cyber threat actors ran a malicious SEO-poisoning campaign that impersonated Google Gemini CLI and Anthropic Claude Code to push malicious downloads. The operation...
SHub Reaper macOS infostealer variant
Malware Activity
H score23
First: 19.05.2026 00:42
Last: 19.05.2026 00:42
Sources 1
About this happening:
The SHub Reaper macOS infostealer now uses AppleScript and a fake Apple security update lure to infect Macs, raising the risk of credential theft and remote access. It...
SHub Reaper macOS infostealer variant
Malware ActivityAbout this happening: The SHub Reaper macOS infostealer now uses AppleScript and a fake Apple security update lure to infect Macs, raising the risk of credential theft and remote access. It...
ClickFix Windows Terminal Lumma Stealer campaign
Campaign
H score35
First: 06.03.2026 08:44
Last: 06.03.2026 08:44
Sources 1
About this happening:
A widespread ClickFix campaign is abusing Windows Terminal (wt.exe) to run malicious commands and deploy Lumma Stealer, expanding the risk of credential theft and brow...
ClickFix Windows Terminal Lumma Stealer campaign
CampaignAbout this happening: A widespread ClickFix campaign is abusing Windows Terminal (wt.exe) to run malicious commands and deploy Lumma Stealer, expanding the risk of credential theft and brow...
Timeline
-
26.07.2026 01:37 2 articles · 1h ago
Fake Steam troubleshooting replies install XMRig miners on Windows
Initial DisclosureThreat actors are abusing Steam discussion forums with ClickFix replies that tell users to open PowerShell as administrator and run a supposed fix for game crashes, lost inventory items, or other computer problems, but the command downloads and launches an XMRig miner, creates a Microsoft Defender exclusion for C:\Windows\Background, and sets persistence with a scheduled task named XMRig-[computer name].
Show sources
- Steam forum ClickFix attacks infect gamers with XMRig cryptominers — www.bleepingcomputer.com — 26.07.2026 01:37
- Steam forum ClickFix attacks infect gamers with XMRig cryptominers — www.bleepingcomputer.com — 26.07.2026 01:37