Steam Workshop abused to spread malware via Wallpaper Engine app

2026-06-16T19:23:28Zfb7e7376e2794ed4f6cbff2d99c53d6b06fe93e611636c31054b788994f666de
cisco-sd-wancpanelcrypto-scamsdata-breachdeepfakeevasion-techniquefortinet-fortisandboxghosttreeiRhythmimposter-scamslitespeedmalware-distributionmicrosoft-defendermicrosoft-teamsntfs-junctionsopenid-connectoptinmonsterransomwarescamssimplehelpsprysockssteam-workshopsupply-chainwallpaper-enginewordpress-cdn

What happened

Multiple actively exploited vulnerabilities and widespread abuse campaigns were reported: threat actors are using Steam Workshop wallpaper packages to distribute malware and DragonForce ransomware is hiding C2 traffic in Microsoft Teams relays. Researchers disclosed GhostTree, an NTFS recursive-junction evasion technique that can disrupt Defender scans. CISA warned of an actively exploited LiteSpeed cPanel plugin flaw (CVE-2026-54420); Cisco released fixes for an exploited SD‑WAN vManage zero-day (CVE-2026-20262); and critical Fortinet FortiSandbox flaws are being exploited. Additional notable

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
fb7e7376e2794ed4f6cbff2d99c53d6b06fe93e611636c31054b788994f666de
Enrichment time
2026-06-16T19:23:28Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Steam Workshop abused to spread malware via Wallpaper Engine app · Baitaphish