Critical

Steam forum ClickFix attacks infect gamers with XMRig cryptominers

BleepingComputer
Actively Exploited

Overview

Gamers using Steam forums are facing a new threat from ClickFix attacks, where attackers pose as helpful users offering solutions to game or computer issues. However, these purported fixes actually contain XMRig cryptominers, which secretly install on victims' devices to mine cryptocurrency without their consent. This not only affects the performance of users' computers but can also lead to increased electricity costs and potential hardware damage. Anyone who frequents these forums should be cautious and avoid downloading or executing unknown files, as this type of malware can significantly degrade their system's performance. The situation highlights the need for vigilance in online communities, especially where users seek help for technical problems.

Key Takeaways

  • Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
  • Affected Systems: Steam discussion forums, users downloading malicious files
  • Action Required: Users should avoid downloading files from untrusted sources and verify the legitimacy of any fixes suggested on forums.
  • Timeline: Newly disclosed

Original Article Summary

Steam discussion forums are being abused in ClickFix attacks that pretend to be fixes for game and computer problems but actually infect devices with cryptominers. [...]

Impact

Steam discussion forums, users downloading malicious files

Exploitation Status

This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.

Timeline

Newly disclosed

Remediation

Users should avoid downloading files from untrusted sources and verify the legitimacy of any fixes suggested on forums. Regularly updating antivirus software can also help detect and prevent such infections.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to Malware.

Related Coverage

GitHub, PyPI add time-absed defenses against supply chain attacks

BleepingComputer

GitHub and the Python Package Index (PyPI) have rolled out a new time-based defense within their Dependabot tool to combat supply chain attacks. This mechanism aims to reduce the potential damage from such attacks by limiting the timeframe in which dependency updates can be exploited. Supply chain attacks have been a growing concern, as they can affect countless projects by targeting the libraries and packages they rely on. By implementing this time-based approach, GitHub and PyPI are enhancing security for developers and users who depend on their platforms. This change is particularly important as the software ecosystem continues to grow, making it a key area for ongoing security improvements.

Jul 26, 2026

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 107

Security Affairs

The Security Affairs Malware Newsletter discusses recent malware threats, including a backdoor introduced through compromised RubyGems like SleeperGem, Dendreo, and fastlane. These malicious packages can allow attackers to maintain persistent access to affected systems. Additionally, the report highlights the chaos caused by over 800 fake AI skills and MCP servers that delivered malware to unsuspecting users. The newsletter also mentions a ransomware variant called msaRAT that poses further risks. These developments are significant as they illustrate the evolving tactics used by cybercriminals, affecting developers and users who rely on these tools. Companies and users should remain vigilant and ensure their software sources are secure to prevent such incidents.

Jul 26, 2026

Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Credentials

Security Affairs

Hackers have taken advantage of compromised hotel Wi-Fi gateways to trick users into entering their Microsoft 365 credentials on fake login pages. According to research from ReliaQuest's threat team, attackers have targeted hotels and conference centers, redirecting guests without their knowledge. This method avoids traditional phishing tactics like emails or attachments, making it particularly sneaky. Anyone using hotel Wi-Fi could be at risk, especially business travelers who often access sensitive accounts. This incident serves as a reminder for users to be cautious when logging into accounts over public networks and to verify the authenticity of login pages.

Jul 26, 2026

Security Affairs newsletter Round 587 by Pierluigi Paganini – INTERNATIONAL EDITION

Security Affairs

Iran-linked actors have been identified as targeting critical infrastructure in the United States, specifically focusing on water and energy control systems. This escalation raises alarms about the security of essential services that millions rely on. The attacks pose significant risks, as breaches in these systems could lead to disruptions in water supply and energy distribution, impacting daily life and public safety. The involvement of state-sponsored groups highlights the ongoing geopolitical tensions and the potential for cyber warfare to affect civilian infrastructure. Organizations managing these essential services need to enhance their security measures to defend against such sophisticated threats.

Jul 26, 2026

How to Secure AI Applications in Production

SCM feed for Latest

AI applications face significant security challenges at three critical points: system prompt integrity, output handling, and runtime visibility. These weaknesses can lead to various vulnerabilities, including data leaks or malicious outputs that could mislead users or systems. Organizations deploying AI solutions need to address these issues to protect sensitive information and ensure reliable performance. Failure to secure these aspects can result in serious consequences, including loss of trust from users and potential regulatory scrutiny. It’s crucial for companies to implement robust security measures at these control points to mitigate risks associated with AI deployment.

Jul 26, 2026

Week in review: ServiceNow pre-auth RCE exploited in the wild, Hugging Face breached

Help Net Security

Last week, it was reported that a pre-authentication remote code execution (RCE) vulnerability in ServiceNow was actively exploited in the wild. This vulnerability allows attackers to execute arbitrary code on affected systems without needing to authenticate, posing significant risks to organizations using the platform. In a separate incident, Hugging Face, a popular AI community, experienced a data breach, although details about the extent of the breach and the data compromised have not been fully disclosed. These incidents highlight ongoing security challenges for companies leveraging AI and cloud services, as they must remain vigilant against potential exploits that can have serious consequences for their operations and data integrity.

Jul 26, 2026