PSA: Don’t execute PowerShell commands proffered by Steam forum randos, because it could infect your rig with a cryptominer

Steam discussions can be the best route to a quick fix or otherwise answering your most burning gaming questions. These forums can also be a hive of scum and villainy. Case in point, bad actors have been taking to the Steam forums with fake fixes that end up installing cryptominers on your gaming PC.

An innocent Steam user will post on the discussion board, sharing an issue they’re having with their game. A bad actor then replies in the thread, instructing the user to run PowerShell as an administrator, and then to enter a specific command. This will be presented as a fix, but executing the command will actually download and then launch an executable for an XMRig cryptominer.

Bleeping Computer was the first to report on this style of attack happening across the Steam forums. They note that threat actors had recently targeted posts asking for help with everything from missing in-game items, to crashes.

As the user is instructed to input the code themselves, the cryptominer download sidesteps the sort of security checks that would otherwise cut malicious executable code off at the knees. Called ClickFix, social engineering-style attacks like this are often so elegant, and so devastating to fall prey to. So, consider this your friendly reminder to not just execute operating system commands proffered by Steam forum randos. This trap is a specifically Windows attack, but the advice remains true if you are, say, new to gaming on Linux where trusting someone else’s commands can sometimes feel like the only recourse.

Leave a Comment