The WeedHack malware campaign continues to target Minecraft players by shifting distribution tactics to file-hosting services after security researchers dismantled the operation's original command-and-control infrastructure in July.
Key Points
- McAfee researchers blocked over 6,300 attempts to access malicious WeedHack sites in the past month.
- The campaign has infected more than 116,464 gamers by impersonating legitimate Minecraft clients through SEO poisoning.
- Attackers now primarily distribute malware via Discord, which accounts for 49.6% of identified malicious links.
- Other distribution channels include MediaFire, GitHub, Dropbox, and websites mimicking official Minecraft resellers.
- Threat actors are utilizing AI-powered platforms to rapidly create deceptive websites that lure users with free versions of paid software.