Researchers report that the WeedHack malware campaign is still infecting people through convincing fake Minecraft client/mod websites, even after its command-and-control server was disrupted. Attackers use SEO poisoning and trusted community platforms (like Discord and Minecraft modding sites) to push malicious downloads that steal passwords, cookies, and crypto wallets.
How the attack works
The WeedHack campaign targets Minecraft players by impersonating popular clients and mods. Attackers build polished fake websites that copy the real tool's features, FAQs, installation steps, developer information, and even links to legitimate GitHub repositories. This mix of real and fake content makes the sites look detailed and convincing, so most users have little reason to suspect anything.
Distribution relies on two main channels. First, SEO poisoning pushes fake sites to the top of Google search results, as seen when the first two results for a popular client called Xenon Client both led to WeedHack-distributing pages. Second, Discord communities are used to promote fake downloads, including one channel promoting a fake client that had more than 1,900 members. File hosting services like MediaFire and Dropbox are also used to host the actual malicious files.
Why it keeps succeeding
Even after the WeedHack command-and-control infrastructure was disrupted, researchers still found active malicious sites and file-hosting accounts continuing to spread the malware. Several factors explain why the campaign persists:
- Many legitimate Minecraft tools never had an official website, only a GitHub page and a Discord server, which leaves an opening for attackers to build a convincing "official" site from scratch
- Fake sites link to real GitHub repositories, borrowing legitimacy from genuine projects
- Large, active-looking Discord communities create a false sense of trust regardless of member count
- One fake site alone offered eight different mods that all delivered the same malware, showing the scale of the operation
What to watch for
- A brand-new "official" website for a tool that has historically only existed as a GitHub repo or Discord server
- Generic team names in a credits section instead of real developer information
- Download prompts routed through third-party file hosts rather than an official repository
- Any installer that asks you to disable antivirus protection before running
Building resistance
The most reliable defense is sourcing software only from official developer repositories or trusted platforms such as Modrinth and CurseForge, rather than trusting search results or Discord links. Treat any request to disable antivirus protection as a strong signal of malware. Security awareness efforts for gaming-adjacent audiences, including general staff, students, interns, and IT support teams who field related questions, should reinforce that a professional-looking site or an active-looking community is not proof of legitimacy.
Key findings
- McAfee observed ongoing distribution via “ten active malicious sites and multiple file-hosting accounts” even after WeedHack’s C2 disruption.
- Attackers rely on brand impersonation and highly convincing fake sites that copy “features, FAQs, installation steps, developer information and even links to legitimate GitHub repositories.”
- SEO poisoning is used so fake sites appear at the top of Google results (example given: searches for “Xenon Client”).
- Distribution heavily leverages trusted platforms and services: Discord, file hosting (MediaFire/Dropbox), and GitHub links.
- Victims are prompted to download and run Minecraft clients/mods that deliver an infostealer (cookies, passwords, browser data, crypto wallets).
Who’s being targeted
- Commonly targeted roles: All employees (general security awareness), IT support/helpdesk (user reporting and guidance), Students/Interns / early-career staff, Employees who install games/mods on work or unmanaged devices.
- Affected industries: Online gaming communities, Consumer internet users (gamers), Social media and community platforms, File hosting platforms.
- Attack channels: website, discord.
- Impersonated: A popular Minecraft client/mod brand (e.g., “Xenon Client”), Minecraft server/mod community (e.g., DonutSMP client promoters), Nova Client / Crystal PVP mod.
Red flags to watch for
- A polished site that still isn’t the official developer source (only links to the real GitHub)
- Generic/incorrect developer credits or team information
- Download prompts that don’t match the official distribution channel (e.g., only a GitHub/Discord exists for the real project)
- Unverified Discord channels pushing executable downloads
- Large communities can still be untrustworthy (member count is not proof)
- Downloads routed through third-party hosting rather than an official repo
- A tool that historically had no official website suddenly has one
- Credits section uses generic team names instead of real developers
- Site appears above the genuine GitHub repository in search results
Frequently asked questions
What is WeedHack malware?
WeedHack is an infostealer distributed through fake Minecraft client and mod websites that steals cookies, passwords, browser data, and crypto wallets from infected devices.
How do attackers get victims to download WeedHack?
Attackers use SEO poisoning so fake sites rank at the top of Google searches for popular Minecraft clients, and they also promote malicious download links inside Discord communities.
Why do these fake Minecraft sites look so convincing?
The fake sites copy the real tool's features, FAQs, installation steps, and developer information, and some even link to legitimate GitHub repositories to appear authentic.
How can users avoid downloading fake Minecraft clients?
Only download mods and clients from official developer repositories or trusted platforms such as Modrinth and CurseForge, and be suspicious of any tool that suddenly has a new official website.
Read the video transcript
You Google “Xenon Client” for Minecraft, click the top result… and quietly install WeedHack malware instead. Researchers found those top Xenon Client results were fake sites pushing WeedHack. They copy the real features, FAQs, even link to the legit GitHub, but the download is an infostealer that nabs cookies, passwords, and crypto wallets. And it’s not just Google. McAfee saw almost half of malicious links coming from Discord, servers hyping a 'DonutSMP client' or packs of mods, all routed through MediaFire or Dropbox, all dropping the same WeedHack payload. Here’s the move: if a Minecraft client or mod isn’t coming from the project’s real GitHub, Modrinth, or CurseForge, and especially if the installer asks you to disable antivirus, back out and report the link to security.