Fake Steam ‘Fixes’ Distribute XMRig via the ClickFix Technique, Quietly Turning Gamers’ PCs Into Cryptominers 

Published
Written by:
Lore Apostol
Lore Apostol
Cybersecurity Writer
Key Takeaways
  • Attack method: Threat actors create fake Steam accounts to post malicious PowerShell commands disguised as game fixes.
  • Malware payload: The script downloads an XMRig cryptominer and installs it as system.exe.
  • Persistence setup: It adds a Microsoft Defender exclusion and creates a scheduled task named "XMRig-[computer name]."

Steam discussion forums are being abused in ClickFix attacks that pose as fixes for game and computer problems but instead infect devices with cryptominers such as XMRig. Threat actors create random Steam accounts and reply to posts about game crashes, lost inventory items, and other technical headaches. 

They tell members to open PowerShell as an administrator and run a command to "fix" it, which quietly downloads an XMRig miner executable and launches it instead.

ClickFix red flags

The website asks you to press Win + R
The website tells you to open PowerShell, Command Prompt, or Terminal
The website asks you to paste the clipboard contents
Verification requires running a Windows command

ClickFix Steam Campaign Deliver Cryptominer

ClickFix is a social engineering tactic built on fake errors, verification prompts, or troubleshooting steps designed to get victims to run malicious commands themselves. Because the user is the one hitting Enter, the attack often slips past security tools that would otherwise flag it automatically.

Forum post pushing the ClickFix social engineering attack | Source: BleepingComputer
Forum post pushing the ClickFix social engineering attack | Source: BleepingComputer

Fake Windows Optimizer Hides XMRig Miner

The PowerShell script masquerades as a Windows optimization utility called "msf utility \ PC Opt," BleepingComputer reported, citing a reader tip. It shows messages claiming to clean temporary files, flush the DNS cache, update drivers, scan for malware – mostly just fake progress bars. 

The real work happens in a function called “Advanced-Optimization,” which disables TLS certificate validation and checks for administrator privileges before doing anything real. 

It creates the C:\Windows\Background directory, adds it as a Microsoft Defender exclusion, then downloads the payload. A scheduled task named "XMRig-[computer name]" launches it with SYSTEM privileges every time the machine starts.

How to Tell If Your PC Has a Cryptominer

High, sustained CPU usage is the giveaway, leading to worse game performance, overheating, higher power bills, and faster hardware wear.

Users Should Never Run Unknown Commands

The advice here isn't complicated: never run a PowerShell command posted by a stranger in a forum, no matter how convincingly it's framed as a fix.

For affected Steam users:

Among the latest seen cases are fake Google and Cloudflare verification pages distributing StealC, Amatera, CastleLoader, and New ResiLoader earlier this month. Recently, Steam users were targeted with a malicious Steam Workshop Wallpaper Engine hijacking campaign that distributed DarkKomet, Lumma, Vidar, and RenEngine.

A May XLab analysis outlined that attackers leveraged a Ghost CMS SQL Injection vulnerability to facilitate large-scale ClickFix campaigns. Hackers also led a massive XMRig campaign that exploited game torrents over the winter Holidays in 2025.


For a better user experience we recommend using a more modern browser. We support the latest version of the following browsers: For a better user experience we recommend using the latest version of the following browsers: