Steam forum ClickFix attacks infect gamers with XMRig cryptominers
2026-07-26T01:23:37Z•8a6c8519e08d752ea95d619d61c531e97e4b4b8b1f29228d9c46961ec0ae762f
ai-agentai-profilingchick-fil-aclickfixclopcredential-stuffingcryptominerdata-breachdns-hijackingdolphin-xflexplmhermeshotel-wifijavascript-in-memorymalvertisingmicrosoft-365ontracorigin-energyptc-windchillransomwareratsextortionshinyhunterssupply-chain-attack-risked-dependencies (slopsquatting)xmrig
What happened
A collection of security incidents reported by BleepingComputer (24–25 Jul 2026): Steam forums are being abused in “ClickFix” posts that install XMRig cryptominers; a large malvertising campaign uses fake crypto/trading sites and JavaScript to assemble malware in browser memory; sextortion scams leverage email lists leaked by ShinyHunters; multiple data breaches and credential attacks (OnTrac, Origin Energy, Chick‑fil‑A credential stuffing) expose PII and account credentials; hotel/conference Wi‑Fi DNS hijacks are stealing Microsoft 365 credentials via phishing sites; Clop ransomware is now ex
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 8a6c8519e08d752ea95d619d61c531e97e4b4b8b1f29228d9c46961ec0ae762f
- Enrichment time
- 2026-07-26T01:23:37Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.