Fake Minecraft Client Sites Still Push WeedHack

Security Affairs · Medium sophistication
Last updated August 25, 2026

Researchers report that the WeedHack malware campaign is still infecting people through convincing fake Minecraft client/mod websites, even after its command-and-control server was disrupted. Attackers use SEO poisoning and trusted community platforms (like Discord and Minecraft modding sites) to push malicious downloads that steal passwords, cookies, and crypto wallets.

How the attack works

The WeedHack campaign targets Minecraft players by impersonating popular clients and mods. Attackers build polished fake websites that copy the real tool's features, FAQs, installation steps, developer information, and even links to legitimate GitHub repositories. This mix of real and fake content makes the sites look detailed and convincing, so most users have little reason to suspect anything.

Distribution relies on two main channels. First, SEO poisoning pushes fake sites to the top of Google search results, as seen when the first two results for a popular client called Xenon Client both led to WeedHack-distributing pages. Second, Discord communities are used to promote fake downloads, including one channel promoting a fake client that had more than 1,900 members. File hosting services like MediaFire and Dropbox are also used to host the actual malicious files.

Why it keeps succeeding

Even after the WeedHack command-and-control infrastructure was disrupted, researchers still found active malicious sites and file-hosting accounts continuing to spread the malware. Several factors explain why the campaign persists:

  • Many legitimate Minecraft tools never had an official website, only a GitHub page and a Discord server, which leaves an opening for attackers to build a convincing "official" site from scratch
  • Fake sites link to real GitHub repositories, borrowing legitimacy from genuine projects
  • Large, active-looking Discord communities create a false sense of trust regardless of member count
  • One fake site alone offered eight different mods that all delivered the same malware, showing the scale of the operation

What to watch for

  • A brand-new "official" website for a tool that has historically only existed as a GitHub repo or Discord server
  • Generic team names in a credits section instead of real developer information
  • Download prompts routed through third-party file hosts rather than an official repository
  • Any installer that asks you to disable antivirus protection before running

Building resistance

The most reliable defense is sourcing software only from official developer repositories or trusted platforms such as Modrinth and CurseForge, rather than trusting search results or Discord links. Treat any request to disable antivirus protection as a strong signal of malware. Security awareness efforts for gaming-adjacent audiences, including general staff, students, interns, and IT support teams who field related questions, should reinforce that a professional-looking site or an active-looking community is not proof of legitimacy.

Key findings

  • McAfee observed ongoing distribution via “ten active malicious sites and multiple file-hosting accounts” even after WeedHack’s C2 disruption.
  • Attackers rely on brand impersonation and highly convincing fake sites that copy “features, FAQs, installation steps, developer information and even links to legitimate GitHub repositories.”
  • SEO poisoning is used so fake sites appear at the top of Google results (example given: searches for “Xenon Client”).
  • Distribution heavily leverages trusted platforms and services: Discord, file hosting (MediaFire/Dropbox), and GitHub links.
  • Victims are prompted to download and run Minecraft clients/mods that deliver an infostealer (cookies, passwords, browser data, crypto wallets).

Who’s being targeted

  • Commonly targeted roles: All employees (general security awareness), IT support/helpdesk (user reporting and guidance), Students/Interns / early-career staff, Employees who install games/mods on work or unmanaged devices.
  • Affected industries: Online gaming communities, Consumer internet users (gamers), Social media and community platforms, File hosting platforms.
  • Attack channels: website, discord.
  • Impersonated: A popular Minecraft client/mod brand (e.g., “Xenon Client”), Minecraft server/mod community (e.g., DonutSMP client promoters), Nova Client / Crystal PVP mod.

Red flags to watch for

  • A polished site that still isn’t the official developer source (only links to the real GitHub)
  • Generic/incorrect developer credits or team information
  • Download prompts that don’t match the official distribution channel (e.g., only a GitHub/Discord exists for the real project)
  • Unverified Discord channels pushing executable downloads
  • Large communities can still be untrustworthy (member count is not proof)
  • Downloads routed through third-party hosting rather than an official repo
  • A tool that historically had no official website suddenly has one
  • Credits section uses generic team names instead of real developers
  • Site appears above the genuine GitHub repository in search results
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is WeedHack malware?

WeedHack is an infostealer distributed through fake Minecraft client and mod websites that steals cookies, passwords, browser data, and crypto wallets from infected devices.

How do attackers get victims to download WeedHack?

Attackers use SEO poisoning so fake sites rank at the top of Google searches for popular Minecraft clients, and they also promote malicious download links inside Discord communities.

Why do these fake Minecraft sites look so convincing?

The fake sites copy the real tool's features, FAQs, installation steps, and developer information, and some even link to legitimate GitHub repositories to appear authentic.

How can users avoid downloading fake Minecraft clients?

Only download mods and clients from official developer repositories or trusted platforms such as Modrinth and CurseForge, and be suspicious of any tool that suddenly has a new official website.

Read the video transcript

You Google “Xenon Client” for Minecraft, click the top result… and quietly install WeedHack malware instead. Researchers found those top Xenon Client results were fake sites pushing WeedHack. They copy the real features, FAQs, even link to the legit GitHub, but the download is an infostealer that nabs cookies, passwords, and crypto wallets. And it’s not just Google. McAfee saw almost half of malicious links coming from Discord, servers hyping a 'DonutSMP client' or packs of mods, all routed through MediaFire or Dropbox, all dropping the same WeedHack payload. Here’s the move: if a Minecraft client or mod isn’t coming from the project’s real GitHub, Modrinth, or CurseForge, and especially if the installer asks you to disable antivirus, back out and report the link to security.

Similar attacks

GitHub Issue Trick Turns AI Coders Against Repos

GitHub Issue Trick Turns AI Coders Against Repos

Researchers showed that a single public GitHub issue (from someone with no repo access) could steer popular AI coding agents into running dangerous commands, exposing tokens, and changing repositories. The risk comes from AI agents reading untrusted issue/PR text while also having access to…

August 6, 2026
DEF CON Attendees Hit With Fake CoinDesk DMs

DEF CON Attendees Hit With Fake CoinDesk DMs

After Black Hat/DEF CON, cybercriminals allegedly targeted conference attendees by impersonating a CoinDesk executive over X direct messages. Victims were pushed into a realistic workflow using Google Docs and a fake Dropbox DocSend installer to trick them into running malware on macOS or Windows.

August 21, 2026
Attackers Phish via Teams & Slack, Not Email

Attackers Phish via Teams & Slack, Not Email

Research and incident examples show attackers increasingly using trusted collaboration tools (like Microsoft Teams and Slack) to impersonate IT/support or known community members, then push victims to phishing sites, approve MFA prompts, or run malicious files. Because messages come through…

August 20, 2026
Def Con DMs Lure Targets Into Fake Google Docs

Def Con DMs Lure Targets Into Fake Google Docs

A researcher was targeted after Black Hat/Def Con by an attacker posing as a CoinDesk executive and using X direct messages to build trust. The scam used familiar platforms (Google Docs and Dropbox DocSend) to push “ClickFix”-style steps or a fake installer intended to get the victim to run malware.

August 20, 2026
Fake GitHub Repos and Trojan Apps Steal Data

Fake GitHub Repos and Trojan Apps Steal Data

Researchers described two active social-engineering-driven malware campaigns: one uses trojanized “popular” remote-user apps (e.g., Zoom/WebEx lookalikes) to trick people into installing credential and crypto-stealing malware, and another uses hundreds of imposter GitHub repositories to lure…

July 17, 2026
Fake Advisors, ClickFix, and Chrome Sync Spying

Fake Advisors, ClickFix, and Chrome Sync Spying

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale phone-based investment fraud, and stalkers misusing Chrome Sync after brief physical access. The items include clear workflows that can be turned…

July 16, 2026