Ethical Hacking News
The malicious WeedHack malware-as-a-service campaign has continued to spread despite a disruption to its command-and-control infrastructure. The campaign's use of fake Minecraft client websites, YouTube videos linking to malicious downloads, and SEO poisoning has made it difficult for users to distinguish between legitimate and malicious content. According to a recent report, ten active malicious sites and multiple file-hosting accounts are still spreading the infostealer, targeting Minecraft users. The campaign's resilience highlights the need for Minecraft users to be vigilant when downloading and installing mods and clients.
The WeedHack malware campaign has continued to spread despite a disruption to its command-and-control infrastructure. McAfee has identified 10 active malicious sites and multiple file-hosting accounts spreading the infostealer. The campaign uses fake Minecraft client websites, YouTube videos, and SEO poisoning to target users. The operation has logged 116,464 infected systems and added 2,000-3,000 new victims daily. Attackers are using social media platforms like Discord and YouTube to promote malicious content. Discord is the most common source of malicious links (49.6%), followed by MediaFire (23.4%). The campaign has spread through trusted Minecraft communities, making scams harder to spot. McAfee recommends downloading mods and clients only from official developer repositories. The campaign has shown remarkable resilience despite the disruption to its command-and-control infrastructure. The use of legitimate websites and platforms to host malicious content is a common tactic used by cybercriminals. The cost and technical skill required to launch a convincing fake gaming site are now close to zero. Minecraft users must be vigilant when downloading and installing mods and clients to avoid the WeedHack malware.
The malicious WeedHack malware-as-a-service campaign, first spotted in early June 2026, has continued to spread despite a disruption to its command-and-control infrastructure. According to a recent report published by McAfee Labs, ten active malicious sites and multiple file-hosting accounts are still spreading the infostealer, targeting Minecraft users. The campaign's use of fake Minecraft client websites, YouTube videos linking to malicious downloads, and SEO poisoning has made it difficult for users to distinguish between legitimate and malicious content.
WeedHack was first identified as a Malware-as-a-Service operation that had been running since January 2026, logging 116,464 infected systems and adding between 2,000 and 3,000 new victims every day. The operation offered a free tier that anyone with a Discord account could access, a premium tier with webcam surveillance capability for $5 a month, and a dashboard letting operators view stolen credentials, configure custom payloads, and monitor victims in real time.
The campaign's use of search engine optimization (SEO) poisoning has allowed it to push fake sites to the top of search results for popular Minecraft tool names. This has made it easy for users to download the malware without realizing it. The attackers have also used social media platforms like Discord and YouTube to promote their malicious content.
McAfee researchers found that most malicious links came through Discord (49.6%), followed by MediaFire (23.4%), GitHub (8.2%), and Dropbox (4.6%). One Discord channel promoting fake DonutSMP clients had more than 1,900 members, while another site offered eight different mods that all delivered the same malware.
The campaign has also spread through trusted Minecraft communities such as Planet Minecraft and EndMods, making the scams harder to spot. McAfee recommends downloading mods and clients only from official developer repositories or trusted platforms such as Modrinth and CurseForge. If a tool asks you to disable antivirus protection, treat it as malware.
Despite the disruption to its command-and-control infrastructure, the WeedHack campaign has shown remarkable resilience. The attackers have shifted their tactics, removing the dashboard and distribution sites, but leaving the malicious sites active. This has allowed them to continue spreading the malware and infecting new victims.
The use of legitimate websites and platforms to host malicious content is a common tactic used by cybercriminals. In this case, the attackers used a fake website for a client that had no real website, and even used an AI-powered web application builder to create convincing fake gaming sites. This has made it easier for them to launch new campaigns without requiring specialized technical skills.
The cost and technical skill required to launch a new convincing fake gaming site are now close to zero, thanks to the availability of tools like lovable.app. This platform accepts natural language instructions and produces working sites, making it easy for attackers to create convincing fake websites.
The spread of the WeedHack malware highlights the need for Minecraft users to be vigilant when downloading and installing mods and clients. It also emphasizes the importance of using reputable sources and checking the authenticity of websites and platforms before downloading any content.
In conclusion, the Fake Minecraft Sites Continue to Spread Malicious WeedHack Malware Despite Command and Control Infrastructure Disruption is a serious threat to Minecraft users. The attackers' use of fake websites, SEO poisoning, and social media platforms has made it easy for them to spread the malware and infect new victims. It is essential for users to be aware of the risks and take steps to protect themselves, such as downloading mods and clients only from official developer repositories or trusted platforms, and disabling antivirus protection when installing new tools.
Related Information:
https://www.ethicalhackingnews.com/articles/Fake-Minecraft-Sites-Continue-to-Spread-Malicious-WeedHack-Malware-Despite-Command-and-Control-Infrastructure-Disruption-ehn.shtml
https://securityaffairs.com/197784/malware/fake-minecraft-sites-are-still-spreading-weedhack-after-c2-takedown.html
Published: Tue Aug 25 03:46:57 2026 by llama3.2 3B Q4_K_M