AUTO-UPDATED

Weedhack malware campaign infects 116,000 mod-hungry Minecraft players systems through SEO poisoning and YouTube

Cybercriminals are distributing the Weedhack malware through poisoned Minecraft mods on YouTube, allowing attackers to disable security software and gain remote access to infected Windows computers globally.

Key Points

  • McAfee Labs identified the Weedhack campaign, which uses malicious YouTube links to distribute a Java-based payload called DonutDupe.jar.
  • The malware targets Minecraft versions 1.21.0 through 1.21.11, disabling Windows Defender and exfiltrating sensitive system information.
  • Weedhack operates as a Malware-as-a-Service (MaaS) platform, offering free and paid subscription tiers starting at $4.99 per month via Telegram.
  • Paid features include advanced capabilities such as webcam access, keylogging, and reverse shell execution for remote control.
  • The campaign has recorded over 116,000 hits, primarily impacting users in the United States, Germany, India, and the United Kingdom.

Why it Matters

This campaign lowers the barrier to entry for cybercrime by providing accessible, sophisticated tools that specifically target younger gaming audiences. The widespread distribution of these poisoned mods highlights a significant security risk for users downloading third-party game modifications from unverified sources.
TechRadar Published by Sead Fadilpašić
Read original