Cybersecurity firm McAfee has identified a new "WeedHack" malware campaign that infects users by disguising malicious software as popular Minecraft mods and clients across various online platforms.
Key Points
- WeedHack operates as a "Malware-as-a-service" platform, allowing users to purchase subscriptions starting at $5 per month for advanced features like keyloggers and webcam access.
- The malware spreads through SEO poisoning and deceptive links on sites like Discord and Reddit, targeting younger users who download unofficial Minecraft content.
- Once installed, the virus bypasses Windows Defender, steals browser cookies and cryptocurrency credentials, and grants attackers remote access to the host computer.
- The threat actor behind WeedHack maintains a community website featuring tutorials, feature request boards, and leaderboards to encourage subscribers to maximize their number of victims.
- The initial payload is delivered as a Java Archive (JAR) file, which mimics the legitimate file format used by the official Minecraft client to avoid detection.