Find notable cyber news and cases, enriched with sources, timelines, and signals.

XMRig cryptominer delivered via Steam ClickFix PowerShell

Malware Activity
First reported
Last updated
Happening score
H score 21
1 unique sources, 1 articles

Summary

Hide ▲

A ClickFix lure on Steam discussion forums now turns fake troubleshooting replies into XMRig infections on Windows computers. Victims are told to run an administrator PowerShell command, and the command quietly downloads the miner from msfconfig[.]icu and launches it locally. The payload also creates a Microsoft Defender exclusion and sets up startup persistence, increasing the chance the miner stays active.

Related Happenings

Steam discussion forums ClickFix campaign deploying XMRig miners

Campaign
H score34 First: 26.07.2026 01:37 Last: 26.07.2026 01:37 Sources 1

How related: Steam discussion forums are being abused in ClickFix attacks that pretend to be fixes for game and computer problems but actually infect devices with cryptominers.

About this happening: An ongoing ClickFix campaign on Steam discussion forums is tricking users into running PowerShell commands that install XMRig cryptominers. The operation abuses he...

GPU cryptomining malware using ScreenConnect and SEO poisoning

Malware Activity
H score16 First: 28.05.2026 00:31 Last: 28.05.2026 00:31 Sources 1

About this happening: A cryptojacking malware operation is spreading through SEO-poisoned download pages and, in some cases, AI chatbot recommendations, putting high-performance Windows s...

Fake Gemini CLI and Claude Code SEO-poisoning infostealer campaign

Campaign
H score33 First: 22.05.2026 14:30 Last: 22.05.2026 14:30 Sources 1

About this happening: Cyber threat actors ran a malicious SEO-poisoning campaign that impersonated Google Gemini CLI and Anthropic Claude Code to push malicious downloads. The operation...

SHub Reaper macOS infostealer variant

Malware Activity
H score23 First: 19.05.2026 00:42 Last: 19.05.2026 00:42 Sources 1

About this happening: The SHub Reaper macOS infostealer now uses AppleScript and a fake Apple security update lure to infect Macs, raising the risk of credential theft and remote access. It...

ClickFix Windows Terminal Lumma Stealer campaign

Campaign
H score35 First: 06.03.2026 08:44 Last: 06.03.2026 08:44 Sources 1

About this happening: A widespread ClickFix campaign is abusing Windows Terminal (wt.exe) to run malicious commands and deploy Lumma Stealer, expanding the risk of credential theft and brow...

Timeline

  1. 26.07.2026 01:37 2 articles · 1h ago

    Fake Steam troubleshooting replies install XMRig miners on Windows

    Initial Disclosure

    Threat actors are abusing Steam discussion forums with ClickFix replies that tell users to open PowerShell as administrator and run a supposed fix for game crashes, lost inventory items, or other computer problems, but the command downloads and launches an XMRig miner, creates a Microsoft Defender exclusion for C:\Windows\Background, and sets persistence with a scheduled task named XMRig-[computer name].

    Show sources