Steam Workshop abused to spread malware via Wallpaper Engine app
2026-06-16T19:23:28Z•fb7e7376e2794ed4f6cbff2d99c53d6b06fe93e611636c31054b788994f666de
cisco-sd-wancpanelcrypto-scamsdata-breachdeepfakeevasion-techniquefortinet-fortisandboxghosttreeiRhythmimposter-scamslitespeedmalware-distributionmicrosoft-defendermicrosoft-teamsntfs-junctionsopenid-connectoptinmonsterransomwarescamssimplehelpsprysockssteam-workshopsupply-chainwallpaper-enginewordpress-cdn
What happened
Multiple actively exploited vulnerabilities and widespread abuse campaigns were reported: threat actors are using Steam Workshop wallpaper packages to distribute malware and DragonForce ransomware is hiding C2 traffic in Microsoft Teams relays. Researchers disclosed GhostTree, an NTFS recursive-junction evasion technique that can disrupt Defender scans. CISA warned of an actively exploited LiteSpeed cPanel plugin flaw (CVE-2026-54420); Cisco released fixes for an exploited SD‑WAN vManage zero-day (CVE-2026-20262); and critical Fortinet FortiSandbox flaws are being exploited. Additional notable
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- fb7e7376e2794ed4f6cbff2d99c53d6b06fe93e611636c31054b788994f666de
- Enrichment time
- 2026-06-16T19:23:28Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.