Kaspersky warns of malware in anime wallpapers for Wallpaper Engine

Kaspersky says Steam Workshop wallpapers were used to spread malware through Wallpaper Engine

Application wallpapers can run executable code on Windows

Kaspersky researchers say attackers used Steam Workshop and Wallpaper Engine to distribute malware through infected desktop wallpapers.

The campaign involved multiple wallpaper packages uploaded to Steam Workshop. According to Kaspersky, some of them had already reached thousands or tens of thousands of downloads before removal. The company says Steam users in China and Russia were the main targets, with other victims found in Singapore, Hong Kong, Germany, Vietnam, India and Canada.

Source: Kaspersky

Wallpaper Engine itself is not the malware. The issue is tied to “application wallpapers,” one of the supported wallpaper formats. These wallpapers can run executable Windows programs as a desktop background, which allowed attackers to hide payloads inside content that looked like normal user-generated Steam Workshop items.

Kaspersky found two delivery methods. Some wallpapers included malicious EXE files, DLLs or scripts directly in the package. Others hid malware inside password-protected archives, with passwords stored in file names or configuration files. In several cases, the payload executed automatically after the wallpaper was installed and applied.

Steam accounts were the main target

One wallpaper sample found in December 2025 launched a small desktop game while installing malware in the background. Kaspersky says it deployed the DarkKomet backdoor and a modified “AggregatorHost.dll” library designed to locate Steam data and hijack active Steam sessions.

The campaign was not limited to one malware family. Kaspersky says the infected wallpapers were also used to distribute Lumma and Vidar infostealers, RenEngine loader, backdoors, miners and other payloads. The company believes this was likely the work of multiple independent threat actors rather than a single group.

Kaspersky says Steam had removed the identified malicious wallpapers and links before the report was published. The company later updated the report to say malicious wallpapers had been present as early as August 2025. Users who downloaded suspicious application wallpapers are advised to remove them, scan their system and review recent Steam account activity.

Source: Kasperky