Fake Minecraft Sites Keep Spreading WeedHack

eSecurity Planet · Medium sophistication
Last updated September 8, 2026

Attackers are tricking Minecraft players into downloading malware by cloning legitimate mod/client websites and manipulating search results so the malicious pages appear highly ranked. Even after the malware’s command-and-control systems were disrupted, the fake sites and trusted file-hosting links (Discord, MediaFire, GitHub, Dropbox) continued to distribute malicious Java (JAR) downloads that steal credentials and other sensitive data.

Key findings

  • Taking down/disrupting WeedHack’s original command-and-control (C2) infrastructure did not stop distribution via fake Minecraft websites and trusted hosting services.
  • McAfee observed “more than 6,300 attempts to reach malicious WeedHack sites” in a month-long period after disruption.
  • The campaign uses “SEO poisoning and cloned project pages” to push users to download “malicious JAR files.”
  • Attackers abuse trusted platforms for delivery; McAfee’s sample showed “49.6% were Discord links, 23.4% MediaFire, 8.2% GitHub, and 4.6% Dropbox.”
  • WeedHack steals Minecraft session IDs plus broader credential and data types (browser passwords/cookies, crypto wallet data, screenshots, system info).
  • The MaaS model includes a paid ‘premium tier’ adding capabilities such as webcam access, keylogging, and remote control features.

Who’s being targeted

  • Commonly targeted roles: All staff, IT Service Desk, Endpoint/Desktop Support, Security Operations, Students/Interns (where applicable).
  • Affected industries: Gaming/consumer software, Education (student gamers on school devices), General enterprise endpoints (employees installing unapproved software).
  • Attack channels: website, discord.
  • Impersonated: A legitimate Minecraft client/mod project (e.g., “Xenon Client”), A Minecraft mod/client distributor or community sharing ‘download’ links.

Awareness takeaways

  • Don’t trust search ranking as proof a download is safe; verify you’re on the official project site/release channel before downloading mods/clients.
  • Treat ‘mods’ and ‘game clients’ as real software installers, downloading and running a JAR can install credential-stealing malware.
  • Trusted services (Discord, GitHub, Dropbox, MediaFire) can still host malicious downloads, validate the source, not the brand of the hosting site.

Red flags to watch for

  • The page is a cloned/impersonated project site despite looking legitimate (branding, FAQs, GitHub links copied).
  • Trusting search rank as proof of legitimacy (“top Google results”).
  • Download is a JAR from an untrusted or newly registered/unknown domain rather than an official project channel.
  • File is distributed through a third-party hosting link rather than the official project release channel.
  • Trusted-brand abuse: the platform (Discord) is legitimate, but the file may not be.
  • A Java archive (JAR) download for a ‘mod’ should be treated as executable software and verified before use.
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You Google “Xenon Client download,” click the top result, and boom, WeedHack just rode in with your Minecraft mod. The site looks perfect, branding, FAQs, even real GitHub links, but that big Download button is a malicious JAR. WeedHack steals Minecraft session IDs, browser passwords, cookies, even crypto wallet data. McAfee still saw over 6,300 hits to these fake WeedHack sites in a month, mostly through Discord and MediaFire links. The trick: they abuse trusted platforms, so the Discord or Dropbox logo makes the file feel safe. Here’s the move: before you run any Minecraft mod or client JAR, ignore the search rank and the platform logo, go to the project’s official site or release page yourself and only download from there.

Similar attacks

Fake Minecraft Client Sites Still Push WeedHack

Fake Minecraft Client Sites Still Push WeedHack

Researchers report that the WeedHack malware campaign is still infecting people through convincing fake Minecraft client/mod websites, even after its command-and-control server was disrupted. Attackers use SEO poisoning and trusted community platforms (like Discord and Minecraft modding sites) to…

August 25, 2026
Fake Minecraft Clients Push WeedHack Malware

Fake Minecraft Clients Push WeedHack Malware

Attackers are tricking Minecraft players into downloading malware by impersonating popular Minecraft clients and resellers in Google search results. Even after the campaign’s command-and-control infrastructure was taken down, the operation continued by shifting distribution to common file-hosting…

August 25, 2026
Fake Claude & Perplexity Lures Push Malware

Fake Claude & Perplexity Lures Push Malware

Sophos reports real incidents where attackers impersonated well-known AI brands (especially Claude) to trick people into installing malware. The lures included polished fake installer pages that instruct victims to copy/paste commands, and browser extensions that look legitimate via high ratings…

August 21, 2026
Spoofed Portal Drops APT36 Backdoor on Telecoms

Spoofed Portal Drops APT36 Backdoor on Telecoms

The bulletin describes an APT36 (Transparent Tribe) espionage campaign that uses social-engineering lures and spoofed download portals to trick targets into installing a malicious Windows installer. The installer (“TMS_AfghanTelecom.exe”) deploys the PATCHCORD backdoor, which then calls out to…

August 18, 2026
Typosquat RubyGems Stealer Hits Dev Machines

Typosquat RubyGems Stealer Hits Dev Machines

Researchers found 16 look‑alike (typosquatted) RubyGems packages that trick developers into installing a Windows information stealer. The malicious gems run code automatically during installation, pull down additional malware, and then steal browser logins and crypto wallet data before uploading it…

August 18, 2026
BengalSEO Tricks Bing Users Into Malware & Scam Calls

BengalSEO Tricks Bing Users Into Malware & Scam Calls

Researchers uncovered a long-running “SEO poisoning” operation that manipulates Bing search results to push people onto fake support and activation pages. Victims are steered through a chain of redirects to either download a malware-laced ZIP (MayaBot) or be pressured into calling a fake…

September 8, 2026