Attackers are tricking Minecraft players into downloading malware by cloning legitimate mod/client websites and manipulating search results so the malicious pages appear highly ranked. Even after the malware’s command-and-control systems were disrupted, the fake sites and trusted file-hosting links (Discord, MediaFire, GitHub, Dropbox) continued to distribute malicious Java (JAR) downloads that steal credentials and other sensitive data.
Key findings
- Taking down/disrupting WeedHack’s original command-and-control (C2) infrastructure did not stop distribution via fake Minecraft websites and trusted hosting services.
- McAfee observed “more than 6,300 attempts to reach malicious WeedHack sites” in a month-long period after disruption.
- The campaign uses “SEO poisoning and cloned project pages” to push users to download “malicious JAR files.”
- Attackers abuse trusted platforms for delivery; McAfee’s sample showed “49.6% were Discord links, 23.4% MediaFire, 8.2% GitHub, and 4.6% Dropbox.”
- WeedHack steals Minecraft session IDs plus broader credential and data types (browser passwords/cookies, crypto wallet data, screenshots, system info).
- The MaaS model includes a paid ‘premium tier’ adding capabilities such as webcam access, keylogging, and remote control features.
Who’s being targeted
- Commonly targeted roles: All staff, IT Service Desk, Endpoint/Desktop Support, Security Operations, Students/Interns (where applicable).
- Affected industries: Gaming/consumer software, Education (student gamers on school devices), General enterprise endpoints (employees installing unapproved software).
- Attack channels: website, discord.
- Impersonated: A legitimate Minecraft client/mod project (e.g., “Xenon Client”), A Minecraft mod/client distributor or community sharing ‘download’ links.
Awareness takeaways
- Don’t trust search ranking as proof a download is safe; verify you’re on the official project site/release channel before downloading mods/clients.
- Treat ‘mods’ and ‘game clients’ as real software installers, downloading and running a JAR can install credential-stealing malware.
- Trusted services (Discord, GitHub, Dropbox, MediaFire) can still host malicious downloads, validate the source, not the brand of the hosting site.
Red flags to watch for
- The page is a cloned/impersonated project site despite looking legitimate (branding, FAQs, GitHub links copied).
- Trusting search rank as proof of legitimacy (“top Google results”).
- Download is a JAR from an untrusted or newly registered/unknown domain rather than an official project channel.
- File is distributed through a third-party hosting link rather than the official project release channel.
- Trusted-brand abuse: the platform (Discord) is legitimate, but the file may not be.
- A Java archive (JAR) download for a ‘mod’ should be treated as executable software and verified before use.
Read the video transcript
You Google “Xenon Client download,” click the top result, and boom, WeedHack just rode in with your Minecraft mod. The site looks perfect, branding, FAQs, even real GitHub links, but that big Download button is a malicious JAR. WeedHack steals Minecraft session IDs, browser passwords, cookies, even crypto wallet data. McAfee still saw over 6,300 hits to these fake WeedHack sites in a month, mostly through Discord and MediaFire links. The trick: they abuse trusted platforms, so the Discord or Dropbox logo makes the file feel safe. Here’s the move: before you run any Minecraft mod or client JAR, ignore the search rank and the platform logo, go to the project’s official site or release page yourself and only download from there.