AUTO-UPDATED

Fake Minecraft Clients Deliver WeedHack Malware Despite Infrastructure Takedown

The WeedHack malware campaign continues to target Minecraft players by shifting distribution tactics to file-hosting services after security researchers dismantled the operation's original command-and-control infrastructure in July.

Key Points

  • McAfee researchers blocked over 6,300 attempts to access malicious WeedHack sites in the past month.
  • The campaign has infected more than 116,464 gamers by impersonating legitimate Minecraft clients through SEO poisoning.
  • Attackers now primarily distribute malware via Discord, which accounts for 49.6% of identified malicious links.
  • Other distribution channels include MediaFire, GitHub, Dropbox, and websites mimicking official Minecraft resellers.
  • Threat actors are utilizing AI-powered platforms to rapidly create deceptive websites that lure users with free versions of paid software.

Why it Matters

This campaign highlights the persistent threat of malware-as-a-service models that quickly adapt to infrastructure takedowns by leveraging popular, trusted file-hosting platforms. Gamers remain at significant risk from SEO poisoning, necessitating increased vigilance when downloading third-party mods or software from unofficial sources.
Infosecurity Magazine Published by Kevin Poireault
Read original