Steam Forums Weaponized in ClickFix Cryptominer Campaign
Fake fix posts on Steam discussion forums are walking gamers into running commands that silently install XMRig cryptominers. What happened and what to check.
Steam’s discussion forums are being used as a ClickFix delivery platform. Fake posts that look like community help threads instruct users to run commands that drop XMRig — an open-source Monero cryptominer — on their systems, per BleepingComputer’s reporting on July 25.
What ClickFix is, briefly
ClickFix is a social engineering technique, not an exploit. There’s no vulnerability being patched. The victim’s hands do the work: a post presents a fake “fix” for a game crash, a graphics problem, or a hardware issue, then instructs the user to open PowerShell or a run dialog and paste a command. The command runs with whatever privileges the user has. That’s the entire attack.
The Steam forums vector is a natural fit for this technique. A post in a game’s own community hub — with a Steam profile attached, plausible phrasing, upvotes from other compromised or sock-puppet accounts — reads differently from a random website. Users searching for “game crashing fix” or “black screen on launch” can land there through search results.
What gets installed
XMRig is legitimate open-source software, an efficient CPU miner for Monero (XMR). Threat actors use it because the code is public, easy to configure, and detection coverage is inconsistent across AV products. Once running, it consumes CPU cycles for the attacker’s benefit. The impact on the victim: elevated power consumption, thermal throttling, and sluggish system performance — not credential theft, not ransomware, but not harmless either.
What to do
Before anything else: Valve does not ship fixes through forum posts. Game developers do not ship fixes through forum posts. Any Steam community post that tells you to open a terminal and paste a command is, categorically, not a legitimate fix. If you see one, close it and report it to Steam.
If you ran something from a forum post: Look for it now. Open Task Manager (Windows) or Activity Monitor (macOS) and sort by CPU usage. XMRig typically runs as an unremarkable-looking process name and will sit at 70–100% CPU sustained. A full scan with an updated AV product should catch known XMRig variants — but verify the definitions are current before you trust a clean result. Find the process, kill it, identify how it’s persisting (scheduled task, startup entry, service), and remove the persistence mechanism before declaring the system clean.
Priority call: Medium-low on the threat scale — cryptojacking, not data exfiltration. But a machine that ran an untrusted ClickFix command may have received additional payloads alongside the miner. Treat the endpoint as potentially compromised past XMRig alone, especially if it has access to corporate resources or stored credentials.
Source: Steam forum ClickFix attacks infect gamers with XMRig cryptominers — BleepingComputer, July 25, 2026.
Found this useful? Share it.


