Steam Forums Used to Spread Cryptominer Malware via Fake Fixes
Threat actors target Steam discussion forums in a new ClickFix campaign, creating fake accounts to post seemingly helpful solutions for gamers experiencing crashes, lost inventory items, and other technical issues. The attackers instruct users to open PowerShell as an administrator and run a command that promises to fix their problem. Instead, the command quietly downloads and launches an XMRig cryptominer on the victim's device.
ClickFix attacks rely on social engineering, presenting users with fake error messages, verification prompts, or troubleshooting steps that appear legitimate. Because the victim manually executes the command, the attack can bypass security protections that would normally block malicious code automatically. This particular campaign disguises its payload as a Windows optimization utility called "msf utility \ PC Opt," which displays fake progress messages while performing routine-sounding maintenance tasks.
While the fake utility claims to clean temporary files, flush DNS caches, update drivers, and scan for malware, most of these functions do nothing. The actual malicious activity hides within a function called "Advanced-Optimization," which disables TLS certificate validation and checks for administrator privileges before downloading the cryptominer. Gamers browsing Steam forums should remain cautious of any troubleshooting advice that asks them to run PowerShell commands or download unverified utilities.