Security

Steam Community Mining Malware + Open Secure AI Alliance: Tech Giants Team Up on Safety

Attackers have been posing as helpful players on Steam forums to trick victims into running malicious PowerShell, deploying a miner disguised as 'msf utility / PC Opt.' Separately, Nvidia and other tech majors have formed the Open Secure AI Alliance.

R
By Ravi Menon Security Correspondent
July 28, 2026 / 6 min read

Two security storylines crossed paths this week. On the offensive side, researchers disclosed a Steam-forum-borne cryptominer campaign that disguises itself as a 'PC Opt' or 'msf utility.' On the defensive side, a consortium of major tech companies - led by Nvidia - has launched the Open Secure AI Alliance to coordinate on AI-system security.

How the Steam Campaign Works

The attackers, tracked by BleepingComputer's research team as "SteamGhost," have spent months building reputations on Steam community forums. Their personas pose as experienced players offering free performance-tuning help. The payload arrives as a one-liner PowerShell command, with victims encouraged to paste it into an elevated PowerShell window.

"It looks like a normal 'PC booster' script. It runs, it even shows a fake progress bar, and it improves nothing except the miner's hash rate," said the lead researcher on the disclosure.

The Drop Chain

  • Stage 1: PowerShell one-liner downloads an executable masquerading as "msf utility" or "PC Opt."
  • Stage 2: the executable kills common antivirus processes, then drops an XMRig-class miner.
  • Stage 3: the miner runs in a suspended-process mode to evade task-manager-based detection.
  • Stage 4: persistence is installed via a scheduled task and a registry Run key.

Who Is Affected

Telemetry suggests the campaign has compromised at least 18,000 systems across North America, Europe, and Southeast Asia. The miners have been redirected to a Monero pool that researchers estimate has mined roughly $220,000 in the past six months.

The Open Secure AI Alliance

On the defensive side, Nvidia, Anthropic, Google, Microsoft, and several other major players have formally launched the Open Secure AI Alliance. The Alliance's stated goals include:

  • Shared evaluation suites for AI-system security, including red-team scenarios and jailbreak benchmarks
  • Coordinated disclosure process for vulnerabilities found in AI systems
  • Open tooling for AI-system monitoring, with reference implementations under permissive licenses
  • Policy advocacy for harmonized AI-security regulation across jurisdictions
"We have spent two years arguing about who is responsible for AI security. The Alliance is the answer: shared baselines, shared tooling, shared disclosure," said an Nvidia spokesperson.

Why These Two Stories Mirror Each Other

The Steam campaign is a reminder that old-school social engineering still works. The Open Secure AI Alliance is a reminder that the security industry is preparing for a much harder problem: AI models themselves becoming threat actors. The SteamGhost attackers needed victims to paste a command. A future attacker may not need any human help at all.

What Users Should Do

Never paste unsolicited commands into PowerShell or terminal windows - including from sources that look authoritative. Legitimate tools do not require paste-and-run instructions. The Alliance's website will host a community-curated list of common social-engineering patterns, with a public comment channel for new variants.

Tagged

Comments (0)

No comments yet. Be the first to share your thoughts.