Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Google Adds Selfie Video Recovery for Users Locked Out of Their Accounts

    July 26, 2026

    Robinhood Chain’s real-world assets jump fivefold as tokenized stocks start trading in size

    July 26, 2026

    Oral GLP-1 drugs may quiet the brain’s food craving circuit

    July 26, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Google Adds Selfie Video Recovery for Users Locked Out of Their Accounts
    • Robinhood Chain’s real-world assets jump fivefold as tokenized stocks start trading in size
    • Oral GLP-1 drugs may quiet the brain’s food craving circuit
    • Does Quaker instant strawberries and cream oatmeal contain castoreum from beaver butts?
    • One killed and 16 injured after van crashes into crowd at Berlin Pride | Germany
    • Samsung Galaxy Z Fold 8 Ultra vs. Z Fold 7: How the first ‘Ultra’ foldable compares to last year’s model
    • Sakana AI Releases Fugu-Cyber: An Orchestration Model Reporting 86.9% on CyberGym and 72.1% on CTI-REALM
    • Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Sunday, July 26
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Steam forum ClickFix attacks infect gamers with XMRig cryptominers

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKJuly 26, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Steam discussion forums are being abused in ClickFix attacks that pretend to be fixes for game and computer problems but actually infect devices with cryptominers.

    BleepingComputer learned of the campaign from a reader, who told us threat actors are creating random Steam accounts to post what appears to be helpful fixes for people’s posts about games crashing, lost inventory items, and other technical issues.

    The threat actors reply to posts, telling other members to open PowerShell as an administrator and run a command to fix the issue. However, when executing the command, it quietly downloads an XMRig miner executable and launches it on the computer.

    image
    Forum post pushing the ClickFix social engineering attack
    Forum post pushing the ClickFix social engineering attack
    Source: BleepingComputer

    These types of attacks are known as ClickFix, a social engineering tactic that displays fake errors, verification prompts, or troubleshooting instructions to trick victims into manually executing malicious commands.

    Although ClickFix attacks require interaction from the victim, they are effective because they present users with what appears to be both a legitimate solution for a problem they are having.

    Since the victim manually launches the command, the attack can also bypass some security protections that would otherwise automatically block executed malicious code.

    Fake Windows optimization installs malware

    The PowerShell script distributed in the Steam campaign masquerades as a Windows optimization utility named “msf utility PC Opt.”

    When launched, it displays messages claiming to perform numerous maintenance tasks, including cleaning temporary files, flushing the DNS cache, updating drivers, checking the disk, turning off unnecessary startup items, scanning for malware, repairing the Windows image, and running System File Checker.

    Fake msf utility  PC Opt utility
    Fake msf utility PC Opt utility script
    Source: BleepingComputer

    However, most of these functions do not perform the tasks they claim. Instead, they display fake progress messages and pause for a random period between 1.5 and 8 seconds to make the utility appear legitimate.

    Fake optimizations functions in PowerShell script
    Fake optimizations functions in PowerShell script
    Source: BleepingComputer

    The actual malicious activity is hidden in a function named ‘Advanced-Optimization’, which first disables TLS certificate validation and checks that it is running with administrator privileges. If it is not, the script displays an error stating that administrator rights are required and exits.

    Once running with elevated privileges, the script creates the ‘C:WindowsBackground’ directory and adds it as an exclusion to Microsoft Defender’s scanning functions.

    It also attempts to stop an existing scheduled task named ‘XMRig-[computer name]’ and terminates matching processes named ‘xmrig’ or ‘system’ that are running from the installation directory. It also attempts to delete any XMRig configuration files stored as C:WindowsBackgroundconfig.json.

    It is unclear whether this cleanup is intended to remove leftovers from an earlier install of the same malware or another miner already present on the device.

    The malware then creates a temporary outbound Windows Firewall rule allowing connections to ‘msfconfig[.]icu‘ over TCP port 443 and downloads the XMRig miner payload from https://msfconfig[.]icu:443/tmp/system.txt into a randomly named temporary file.

    Before installing it, the script verifies that the downloaded file is not empty and is a valid executable. If so, it moves the file to C:WindowsBackgroundsystem.exe.

    So it launches every time Windows starts, it will create a new scheduled task named “XMRig-[computer name],” that launches the system.exe executable with SYSTEM privileges.

    As a general rule, users should never run PowerShell commands provided by unknown users in discussion forums, even when the commands are presented as fixes for a problem they are currently experiencing.

    Those who executed the command should check for the ‘C:WindowsBackground’ directory, a Microsoft Defender exclusion for that path, and a scheduled task beginning with ‘XMRig-‘.

    If these signs of compromise are detected, you should immediately run an antivirus program to scan for malware and remove anything it finds.

    If it does not detect the miner, you should manually stop and remove the XMRig-[computer name] scheduled task, remove the Microsoft Defender exclusion for C:WindowsBackground, and delete the folder and its contents.

    Ultimately, it may be safer to reinstall the operating system, as there is no way to know whether the downloaded payload performed additional malicious actions while it was running.


    article image

    Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

    The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

    Get the whitepaper

    attacks ClickFix cryptominers forum gamers infect steam XMRig
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Google Adds Selfie Video Recovery for Users Locked Out of Their Accounts

    Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers

    How Synthetic Identity Fraud is Coming for Machine Identities

    China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks

    Rockwell Patches Code Execution Flaws in Arena Simulation Software

    Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Google Adds Selfie Video Recovery for Users Locked Out of Their Accounts

    July 26, 2026

    Robinhood Chain’s real-world assets jump fivefold as tokenized stocks start trading in size

    July 26, 2026

    Oral GLP-1 drugs may quiet the brain’s food craving circuit

    July 26, 2026

    Does Quaker instant strawberries and cream oatmeal contain castoreum from beaver butts?

    July 26, 2026
    Latest Posts

    Trump slaps 50% tariffs on Canada and Carney vows to ‘intensify’ trade talks

    July 21, 2026

    How Two Brothers Dug for Dead Relatives: With a Shovel and a Kitchen Knife

    July 21, 2026

    Chile floods: Towns evacuated following heavy rain in Coquimbo

    July 21, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Google Adds Selfie Video Recovery for Users Locked Out of Their Accounts

    July 26, 2026

    Robinhood Chain’s real-world assets jump fivefold as tokenized stocks start trading in size

    July 26, 2026

    Oral GLP-1 drugs may quiet the brain’s food craving circuit

    July 26, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.