WeedHack Malware Campaign Targets Minecraft Players Through Fake Mods and YouTube Videos


Security researchers are warning Minecraft players about WeedHack, a malware-as-a-service campaign that spreads through fake Minecraft mods, hacked clients, YouTube videos, and search-poisoned websites. McAfee Labs says the campaign has been active since January 2026 and has logged 116,464 hits, with roughly 2,000 to 3,000 new hits per day.

The campaign matters because it turns the normal search for Minecraft mods into a credential theft and remote access risk. According to the research report, WeedHack has used more than 3,820 malicious JAR files and over 240 distribution URLs to reach players looking for free clients, cheats, utilities, and mod downloads.

WeedHack is not just a single malicious file. It works as a service platform for attackers, with a dashboard that lets customers build payloads, monitor infected systems, view stolen credentials, and follow tutorials on how to spread the malware.

How WeedHack Reaches Minecraft Players

The campaign uses two main distribution methods: YouTube promotion and SEO poisoning. Attackers post polished videos that appear to demonstrate Minecraft mods or clients, then place download links in descriptions, comments, or related pages. Some of these videos use voiceovers and clean editing to look more convincing.

SEO poisoning helps the fake pages appear when players search for popular Minecraft clients or mods. This tactic works especially well when a project has no clear official website, because a malicious page can look like the most trustworthy result to a young player or a casual user.

A separate McAfee security advisory says the campaign has also attracted younger would-be attackers. McAfee says some customers appeared to use the malware not only for account theft, but also to harass victims after gaining access to webcams or files.

What WeedHack Can Steal

Once a player runs the infected JAR file, WeedHack starts a multi-stage infection chain. The malware can collect system details, steal browser data, take screenshots, hijack Minecraft sessions, and deploy further tools for persistence and remote access.

AreaReported WeedHack capability
BrowsersSteals cookies and passwords from 36 browsers
Crypto walletsTargets 56 browser-based wallets and 12 desktop wallets
Gaming and chat accountsTargets Minecraft session IDs, Discord, Steam, and Telegram credentials
Remote accessPremium features can include screen access, webcam access, keylogging, and reverse shell execution
PersistenceUses scripts and scheduled tasks to make removal harder

McAfee says WeedHack also uses EtherHiding, a technique that retrieves the latest command-and-control domain from the Ethereum blockchain. The responses are RSA-signed before execution, which helps the operators protect their infrastructure from outside takeover attempts.

YouTube video promoting malicious Minecraft Mods (Source – McAfee)

The malware has also appeared in public threat tracking. MalwareBazaar lists WeedHack-tagged samples with activity first seen in January 2026 and last seen in May 2026, giving defenders another place to track related files.

Why Minecraft Mods Are an Easy Target

Minecraft has a large modding scene, and many players are used to downloading JAR files from the web. That creates an opening for attackers who can make a fake page look like a normal mod site, especially when they copy names, logos, screenshots, or links to real communities.

The Fabric documentation warns that many websites claim to offer Minecraft mods but are actually malware sites. It recommends using known sources such as Modrinth and CurseForge, checking with others when a source looks unfamiliar, and avoiding suspicious download pages.

WeedHack takes advantage of the same habits. A player sees a video, finds a download link, ignores a warning, and runs a file that looks like a Minecraft tool. From there, the malware can start stealing accounts before the victim understands what happened.

What Players and Parents Should Do Now

Players should treat free Minecraft clients, cracked clients, cheat tools, and mod downloads from unknown websites as high risk. A page that asks users to disable antivirus protection, ignore browser warnings, or run a suspicious JAR file should be treated as unsafe.

  • Download Minecraft mods only from known and trusted platforms or the developerโ€™s verified page.
  • Avoid links in YouTube descriptions, Discord messages, Reddit comments, and file-hosting pages unless the source can be confirmed.
  • Do not disable antivirus protection to install a Minecraft mod or client.
  • Scan suspicious downloads before opening them, but do not rely on scans as the only safety check.
  • Change passwords immediately if a suspicious mod was opened on the device.
  • Enable two-factor authentication on Microsoft, Discord, Steam, Telegram, and crypto wallet accounts where available.

Players can also compare any unfamiliar download page with trusted-source guidance before running a file. If a mod has no clear developer page, no reputable listing, and only appears through search ads, YouTube links, or random mirrors, it should be avoided.

Anyone who already ran a suspicious Minecraft JAR should disconnect from sensitive accounts, change passwords from a clean device, and run security checks. Microsoft says the Microsoft Safety Scanner can find and remove malware from Windows computers, although it does not replace real-time antivirus protection.

Why WeedHack Is Harder to Remove

WeedHack is designed to stay on a system after the first execution. Reports describe scripts that add Windows Defender exclusions and scheduled tasks that can restore removed components. This means a simple file deletion may not remove the full infection.

Screenshot

The campaignโ€™s malware-as-a-service model also makes the threat more scalable. Attackers do not need advanced malware development skills. They can use a dashboard, select options, generate a payload, and follow ready-made distribution instructions.

The safety guidance also warns victims not to follow instructions from someone claiming to have hacked their computer. If a child or teenager receives threats involving stolen files, webcam footage, or account access, they should contact a trusted adult and report the incident instead of engaging with the attacker.

Current WeedHack Indicators

Security teams can use public indicators and malware samples to improve detection. The WeedHack tag on MalwareBazaar provides a sample-focused view of activity, while security vendors have published additional hashes, domains, file names, and detection names tied to the campaign.

Indicator typeExamples reported in public research
Malicious file typeJava JAR files disguised as Minecraft mods or clients
Stage namesDonutDupe.jar, elevator.jar, SecurityManager.jar, component.jar
Windows payload namesTelemetry.exe, RuntimeBroker.exe, chromedriver.dll
Persistence scriptsUpdater.vbs, elv.vbs, WinDefConfig.cmd
Detection namesTrojan:Win/Weedhack and Trojan:Script/Weedhack variants

If a device shows signs of compromise, users should run a full antivirus scan, review startup items, check browser sessions, revoke suspicious logins, and reinstall affected launchers from clean sources. Windows users who need an additional manual check can download the latest scan tool before each scan so it uses current anti-malware definitions.

WeedHack shows how gaming communities remain a valuable target for credential thieves. Minecraft players often search for mods outside official marketplaces, and attackers now combine video marketing, search manipulation, social channels, and low-cost malware tools to reach them at scale.

FAQ

What is WeedHack malware?

WeedHack is a malware-as-a-service campaign that targets Minecraft players through fake mods, hacked clients, YouTube videos, and search-poisoned websites. Once installed, it can steal passwords, account tokens, Minecraft sessions, crypto wallet data, and other sensitive information.

How does WeedHack spread?

WeedHack spreads mainly through fake Minecraft mod websites, YouTube videos, links in descriptions and comments, and SEO poisoning. Attackers try to make malicious download pages look like trusted mod or client pages.

Can WeedHack steal Minecraft accounts?

Yes. WeedHack can target Minecraft session IDs and account-related data. It can also steal credentials from browsers and other apps, which may put Microsoft, Discord, Steam, Telegram, and crypto wallet accounts at risk.

What should I do if I downloaded a suspicious Minecraft mod?

Stop using the affected device for sensitive accounts, change passwords from a clean device, enable two-factor authentication, run a full security scan, and remove suspicious files and startup entries. If someone threatens you with stolen data or webcam access, do not follow their instructions. Report the incident and ask a trusted adult or security professional for help.

How can Minecraft players avoid fake mod malware?

Players should download mods only from trusted platforms or verified developer pages, avoid random links in YouTube, Discord, Reddit, or file-hosting sites, and never disable antivirus protection to run a mod or client.

Readers help support VPNCentral. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help VPNCentral sustain the editorial team Read more

User forum

0 messages