Attackers are posting fake troubleshooting replies on Steam discussion forums that trick gamers into infecting their own Windows PCs with cryptocurrency-mining malware. The campaign uses ClickFix social engineering, telling users to open PowerShell as an administrator and run a command that installs XMRig from msfconfig[.]icu, adds Microsoft Defender exclusions, creates a scheduled task named "XMRig-[computer name]," and persists as C:\Windows\Background\system.exe.
Why it matters: Steam users and home PC owners can be compromised just by following what looks like a helpful forum fix, leading to slowed systems, higher power use, and weakened defenses. People should avoid running PowerShell commands from forum posts, and anyone who did should check for XMRig processes, scheduled tasks, Defender exclusions, and the C:\Windows\Background\system.exe file.
Lawrence Abrams
2026.07.25
100% relevant
This article appears to be the first concrete report tying a live ClickFix campaign to Steam discussion forums and documenting the specific XMRig installer behavior and infrastructure.
← Back to all stories