ClickFix Trojan Leverages Steam Community Forums to Deploy XMRig Cryptominers at Scale
Threat actors are posting fake technical support threads on Steam discussion forums linking to ClickFix malware, which executes XMRig cryptocurrency miners on victim systems. The attack exploits the high trust and technical audience of Steam's community to achieve broad distribution among gamers.
Affected
The ClickFix campaign represents a mature shift in malware distribution strategy. Rather than relying on phishing emails or compromised websites, threat actors are weaponising Steam's discussion forums by posing as legitimate technical support providers offering fixes for common gaming issues. This social engineering angle is effective because gamers actively seek troubleshooting advice in these spaces and are conditioned to trust peer-provided solutions.
ClickFix itself is not novel malware, but its deployment mechanism here is operationally significant. The malware executes XMRig, an open-source CPU miner for Monero, which remains a popular choice for cryptomining botnets because Monero transactions are relatively private compared to Bitcoin. Infected systems contribute computing power to attacker-controlled mining pools while experiencing performance degradation, battery drain, and increased electricity consumption.
The attack surface is broad. Steam has tens of millions of monthly active users, many of whom are technically unsophisticated enough to follow suspicious links when presented as legitimate fixes, yet valuable enough as computing resources to justify the campaign. The forum moderation lag typical of large communities creates a window for malicious threads to accumulate replies and gain visibility before removal.
Defenders should: disable auto-execution of downloads, educate users that official fixes come through Steam client updates or vendor channels (not forum posts), monitor for XMRig process execution and suspicious cryptomining pools, and report malicious threads to Steam moderators. Organisations with gaming communities should consider restricting executable downloads or implementing application whitelisting.
This campaign illustrates how even well-moderated platforms with reputation systems remain vulnerable when attackers blend social engineering with commodity malware. The persistence of ClickFix as a distribution vector suggests attacker ROI remains positive despite active takedown efforts.
Sources