An attack campaign is currently underway in the Steam discussion forums, in which criminals pose as helpers for game and computer problems. Instead of harmless tips, they distribute instructions that infect devices with a cryptomining program.
This affects users who respond to supposed solutions to crashes, lost items or other technical problems. That has Bleeping computer revealed. The attackers rely on a so-called ClickFix pattern. The victims are supposed to open PowerShell with administrator rights and run a command that acts like a repair measure. The command actually downloads an XMRig miner in the background and starts it on the computer.
The malicious script disguises itself as a Windows optimization tool named “msf utilityPC Opt”. It claims to delete temporary files, clear DNS cache, update drivers, check hard drive, disable startups, scan for malware, and repair system files, among other things. However, many of these functions are just a facade. The script displays fake progress messages and pauses for a few seconds at a time to appear serious. The actual malicious function is contained in a separate routine that switches off the validity of TLS certificates in advance and requires administrator rights.
With elevated rights, the script creates a folder under “C:WindowsBackground” and enters this as an exception in Microsoft Defender. It then attempts to terminate existing tasks or processes related to XMRig and delete possible configuration files. It then downloads the miner from an external server and saves it as “system.exe” in the folder. To ensure that the malware runs again every time Windows starts, the script sets up a scheduled task. This starts the file with system rights. It remains unclear whether this is only intended to eliminate remnants of previous installations or whether existing infections are being covered up.
Anyone who has run such a command should look for the “C:WindowsBackground” folder, a Defender exception for that path, and a scheduled task named “XMRig-“. If such traces are found, a complete virus scan is necessary. If in doubt, we recommend reinstalling the operating system because it is not possible to determine with certainty what other actions the malware has already carried out. In general, users should not execute PowerShell commands from forums if they come from unknown people. Even apparently helpful repair instructions can serve as a gateway for malware.
Research Snipers is currently covering all technology news including Google, Apple, Android, Xiaomi, Huawei, Samsung News, and More. Research Snipers has decade of experience in breaking technology news, covering latest trends in tech news, and recent developments.
What should we check before trusting important files to the cloud We often treat cloud…
The social network Twitter is back in a new form: the US startup Operation Bluebird…
The new Xbox Series X25 attracts fans with a chic green case in the style…
Google is expanding personalization for its search, Discover feed and News. A new interactive button…
Take-Two and Rockstar are using all possible means against the attackers operating under the name…
Microsoft is doubling the storage space for Exchange Online mailboxes in certain Microsoft 365 Business…