Steam Malware Campaign, Splunk Exploit, and NGINX Flaws Highlight a Busy Week in Cybersecurity
A year-long malware campaign on Steam's Wallpaper Engine infected tens of thousands, while critical vulnerabilities in Splunk Enterprise and NGINX Open Source are now under active exploitation.
Cybersecurity researchers disclosed multiple significant threats this week, including a year-long malware campaign on Steam that infected tens of thousands of users, active exploitation of a critical Splunk Enterprise vulnerability, and patches for two critical remote code execution flaws in NGINX Open Source. Separately, a massive Android botnet was linked to a publicly traded Israeli firm, and a new North Korean fake IT worker scam network was uncovered.
According to Kaspersky, the Steam campaign abused Wallpaper Engine's "Application Wallpaper" feature, which allows unverified third-party code to run as standalone Windows programs. The attackers distributed malicious wallpapers that, once applied, stole account credentials and hijacked active sessions, with 89% of compromised downloads targeting users in China.
Steam Malware Campaign Details
The attackers used two primary distribution methods: archives containing the executable wallpaper alongside malicious payloads such as .exe files, DLLs, or scripts, and password-protected archives that executed automatically when the wallpaper was applied. One tested wallpaper, containing a malicious game called NTRaholic, dropped a backdoor named Synaptics.exe from the DarkKomet malware family. The campaign also used compromised accounts to upload additional malicious wallpapers to Steam Workshop.
- Dozens of malicious application wallpapers were found on Steam Workshop, some downloaded tens of thousands of times.
- Affected countries beyond China include Germany, Canada, Russia, Singapore, Hong Kong, Vietnam, and India.
- Steam has removed all identified malicious wallpapers, but Kaspersky urges users to run antivirus scans before applying wallpapers with built-in executables.
Splunk and NGINX Vulnerabilities Under Attack
Separately, a critical vulnerability in Splunk Enterprise is now being actively exploited. The flaw involves a PostgreSQL sidecar service endpoint that lacks authentication controls, allowing attackers to access sensitive data. Meanwhile, F5 released patches for two critical NGINX Open Source flaws, CVE-2026-42530 (CVSS v4 score 9.2) and another unnamed vulnerability, both enabling remote code execution. The use-after-free flaw in the ngx_http_v3_module can be triggered by a remote unauthenticated attacker.
In other news, researchers linked the Popa botnet, a four-year-old Android-based botnet that has infected millions of consumer TV boxes, to NetNut, a residential proxy provider operated by the publicly traded Israeli firm Alarum Technologies Ltd (NASDAQ: ALAR). The botnet has been used for advertising fraud, account takeovers, and mass data scraping. Additionally, security firm Nisos uncovered a major North Korean fake IT worker scam network, highlighting the ongoing threat of state-sponsored cybercrime.
Organizations are advised to apply patches for Splunk Enterprise and NGINX Open Source immediately, and Steam users should scan their systems for malware. The breadth of these attacks underscores the need for continuous vigilance across all platforms.
Fact check
-
The Steam malware campaign abused Wallpaper Engine's 'Application Wallpaper' feature and has been ongoing since 2025.
reported · source
-
89% of compromised downloads in the Steam campaign targeted users in China.
reported · source
-
A critical Splunk Enterprise vulnerability involving a PostgreSQL sidecar service endpoint is being actively exploited.
reported · source
-
F5 patched two critical NGINX Open Source flaws, including CVE-2026-42530 with a CVSS v4 score of 9.2.
reported · source
-
The Popa botnet is linked to NetNut, a residential proxy provider operated by Alarum Technologies Ltd.
reported · source
Source reporting (10)
- TechSpot · Cybercriminals have been distributing malware via Steam for a year, tens of thousands affected
- The Stack · Critical Splunk Enterprise vulnerability is now getting exploited
- Krebs on Security · ‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm
- The Hacker News · F5 Patches Two Critical NGINX Open Source Flaws Enabling Remote Code Execution
- TechRadar Pro · 'These actors are no longer relying solely on traditional cybercrime': Experts uncover another massive North Korean fake IT worker scam network
- Slashdot · Google Told Researcher 'Nice Catch!' Then Denied Bug Bounty For Flaw It Still Hasn't Fixed
- TechCrunch · Texas government data breach allowed hackers to steal 3 million driver’s licenses and passports
- SecurityWeek · Majority of Internet-Accessible REDCap Servers Outdated
- The Stack · Accenture acquires majority stake in $3.2bn OT cybersecurity company Dragos
- Gizmodo · The Quantum Threat to Encryption Is Coming. France Just Set a 2027 Deadline
Join the conversation
You need to be registered and logged in to comment on blog articles.
Related Articles
AI Security Threats Shift: MFA Bypass, Crypto Malware, and Shadow AI Access Risks Dominate
Jun 19, 2026
Microsoft Discloses Clipper Malware, RoguePlanet Flaw, and DragonForce Teams Abuse in Same Week
Jun 19, 2026
Ransomware Landscape Shifts: INC RaaS Surges to 830 Victims, Law Enforcement Strikes SocGholish
Jun 19, 2026
0 Comments
No comments yet
Be the first to share your thoughts on this article.