A large malware campaign known as WeedHack is targeting Minecraft players through fake mods, clients, cheats, and utilities, infecting more than 116,000 systems since January.

The malware is being promoted through YouTube videos and SEO poisoning, where attackers push malicious download links that appear in search results for popular Minecraft tools. According to telemetry from cybersecurity company McAfee, WeedHack has already affected 116,464 systems, with around 2,000 to 3,000 new infections recorded every day. Most victims are located in the United States, Germany, India, and the UK.

The scale of the campaign is significant, with researchers identifying more than 240 distribution URLs and 3,820 unique malicious JAR files. McAfee says the attackers mainly lure victims through YouTube videos that promote Minecraft-related tools. Download links are placed in video descriptions and comments, and some of the videos are professionally made with voice-over narration to make them look more legitimate. Some have gathered more than 7,500 views.

The SEO poisoning part of the campaign targets searches for popular Minecraft clients such as Meteor Client, Radium Client, Wurst Client, Aristois, LiquidBounce, Impact Client, Future Client, Inertia Client, Cornos Client, WWE Client, 3arthh4ck, Salhack, Phobos, and Gamesense. McAfee notes that many of these projects do not have official websites and are mainly hosted on GitHub, which makes it easier for fake sites to trick users.

In one case, a malicious website even displayed a warning telling visitors to only download “Skytils” from the official source. It also linked to the real GitHub repository and Discord server, creating a false sense of trust while still pushing a fake and dangerous download.

READ
Steam Forum Scam Tricks Gamers Into Installing Crypto Miner Through Fake PowerShell Fix

WeedHack works as a malware-as-a-service infostealer operation. Unlike most infostealer platforms, it is hosted on the clear web and offers free access to anyone. Users are given a dashboard where they can view infected systems, stolen credentials, victim profiles, and build payloads for Minecraft versions 1.21.0 through 1.21.10.

The free version of WeedHack can steal Minecraft session IDs, browser cookies, saved passwords from 36 browsers, data from 56 cryptocurrency browser extensions, credentials from 12 desktop crypto wallet apps, and accounts linked to Discord, Steam, and Telegram. It can also capture screenshots from infected systems.

The platform also offers a premium version for $5 per month or a $24.99 lifetime purchase. This paid tier adds more intrusive features, including remote control with mouse and keyboard access, webcam access, a keylogger, remote shell, and remote file management.

McAfee says WeedHack’s Telegram channel has more than 800 members, and many of its users appear to be teenagers or young adults using the remote access tools to harass victims.

Minecraft players are advised to download mods only from official project sources, carefully verify links, and avoid running JAR files from unknown or suspicious websites. For users who want the safest way to add new content to the game, the in-game Minecraft Marketplace remains the most trusted option.


Buy ExpressVPN with PayPal or Credit Card

Advertisement