- What: Steam forums used for ClickFix cryptominer attacks
- Impact: Users may unknowingly install cryptominers through deceptive posts
Ransomware , Phishing Steam forums used for ClickFix cryptominer attacks July 27, 2026 Share By SC Staff In a report by Bleeping Computer, threat actors are exploiting Steam discussion forums to distribute cryptominers through a social engineering tactic known as ClickFix. Attackers create fake Steam accounts to post seemingly helpful solutions to users' technical problems. These malicious posts instruct users to open PowerShell as an administrator and execute a command, which secretly downloads and runs the XMRig cryptominer. The PowerShell script disguises itself as a Windows optimization utility, performing fake maintenance tasks while disabling security features like TLS certificate validation and adding the malware's directory to Microsoft Defender exclusions. The miner is downloaded from msfconfig[.]icu and installed as system.exe, with a scheduled task created to ensure it runs on startup with SYSTEM privileges. This method bypasses some security protections because the user manually initiates the malicious command. Users are advised to never run commands from unknown sources on forums and to check for specific indicators of compromise, such as the 'C:WindowsBackground' directory and 'XMRig-' scheduled tasks. If detected, antivirus scans are recommended, and in severe cases, a full operating system reinstallation may be necessary due to the potential for further malicious activity. Source: Bleeping Computer An In-Depth Guide to Ransomware Get essential knowledge and practical strategies to protect your organization from ransomware attacks. Learn More SC Staff Related Phishing Phishing attacks on insurance companies evolve to real-time account hijacking SC Staff July 27, 2026 Phishing campaigns targeting financial institutions are evolving from credential harvesting for later use to real-time account hijacking, based on information published by The Hacker News. Ransomware Botnets powered by residential proxy networks are growing SC Staff July 27, 2026 Botnets powered by residential proxy networks are proliferating, enabling cybercriminals to evade detection by blending in with legitimate traffic, Lumen Technology’s Black Lotus Labs said in a report. Malware Golden Chickens malware-as-a-service resurfaces with four new families SC Staff July 24, 2026 The Hacker News disclosed that the threat actors behind the Golden Chickens malware-as-a-service (MaaS) ecosystem have resurfaced with four new malware families, indicating that the operators are showing no signs of stopping despite extensive public disclosures into their inner workings. Related Events Cybercast Ransomware reloaded: Finding resilience when attackers wield AI On-Demand Event Virtual Conference Ransomware Resilience: Strategies to Defend, Mitigate, and Recover On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe You can skip this ad in 5 seconds