WeedHack malware-as-a-service targets Minecraft players through fake mods
WeedHack is a Minecraft-focused malware-as-a-service campaign that targets players looking for mods, hacked clients, and custom tools. Researchers say the operation steals passwords, browser cookies, cryptocurrency wallet data, Discord tokens, Steam credentials, Telegram data, and Minecraft session information.
The campaign has been active since at least January 2026, according to McAfee Labs. It spreads through search engine poisoning, YouTube videos, Telegram promotion, and fake Minecraft mod websites that lead users to malicious Java Archive files.
Access content across the globe at the highest speed rate.
70% of our readers choose Private Internet Access
70% of our readers choose ExpressVPN
Browse the web from multiple devices with industry-standard security protocols.
Faster dedicated servers for specific actions (currently at summer discounts)
A separate PolySwarm analysis says the WeedHack ecosystem includes more than 3,820 malicious JAR files and over 240 distribution URLs. Operators claim the service has crossed 116,000 hits, with paid access starting at about $5 per month.
How WeedHack reaches Minecraft players
WeedHack relies on a simple lure: players want Minecraft mods, clients, cheats, or performance tools, and attackers create websites and videos that look like safe download pages. The campaign targets searches for popular Minecraft clients such as Meteor Client, Radium Client, Wurst Client, Aristois, LiquidBounce, Future Client, Inertia Client, Phobos, Salhack, and Gamesense.
The malware often arrives as a JAR file, a common format in Java-based Minecraft modding. Because Minecraft players already expect to run Java files, the attack blends into normal gaming behavior more easily than a traditional email attachment.
The Hacker News reported that the campaign uses SEO poisoning and YouTube videos to send victims to malicious Minecraft client pages. McAfee also found two YouTube channels and multiple videos that redirected viewers to WeedHack distribution sites.
| Campaign detail | What researchers found |
|---|---|
| Campaign name | WeedHack |
| Target audience | Minecraft players looking for mods, clients, and cheats |
| Distribution | YouTube, SEO poisoning, fake mod websites, Telegram promotion |
| Main file type | Malicious Java Archive files |
| Claimed scale | More than 116,000 hits |
| Pricing | Free tier and paid access starting at about $5 per month |
The malware uses Ethereum smart contracts for infrastructure
One of WeedHack’s more advanced features is its use of Ethereum blockchain infrastructure to retrieve command-and-control information. This technique, often described as EtherHiding, helps the malware find active infrastructure without relying on one hardcoded server address that defenders can easily block.
After execution, the malware relaunches itself through javaw.exe to reduce visible console activity. It then decrypts embedded Ethereum endpoints and RSA public keys, checks smart contracts for active infrastructure, and verifies responses before moving to the next stage.
The PolySwarm report says WeedHack uses Ethereum smart contracts to retrieve command-and-control details while validating responses with RSA signatures. This makes infrastructure takedowns harder and complicates static detection.
- Initial payloads arrive as Minecraft-themed JAR files.
- The malware uses javaw.exe to run less visibly on Windows.
- Ethereum smart contracts help retrieve live infrastructure details.
- RSA validation helps the malware verify command-and-control responses.
- JNIC obfuscation turns Java bytecode into native code to slow analysis.
What WeedHack steals from infected devices
The free tier of WeedHack already includes extensive information-stealing features. It can capture screenshots, steal Minecraft session IDs, collect system details, extract browser cookies and passwords, and target cryptocurrency wallets.
McAfee says the malware can harvest data from 36 browsers, 56 browser-based cryptocurrency wallets, 12 desktop wallet applications, Discord, Steam, Telegram, and multiple Minecraft launchers. The paid tier adds more invasive remote-access features.
Malware samples tagged as WeedHack on MalwareBazaar show that researchers and malware-sharing communities have tracked samples since January 2026. That timing aligns with the first observed activity described in public research.
| Data or capability | Risk to victims |
|---|---|
| Browser passwords and cookies | Account takeover and session hijacking |
| Minecraft session IDs | Minecraft account hijacking and resale |
| Discord tokens | Impersonation, server abuse, and private message access |
| Steam credentials | Gaming account theft and inventory abuse |
| Cryptocurrency wallets | Wallet draining and seed or key theft |
| Screenshots | Exposure of private chats, accounts, and personal data |
Premium WeedHack features turn infections into remote access
WeedHack’s paid version adds capabilities that go beyond ordinary credential theft. Researchers say premium users can access webcam feeds, keylogging, screen sharing, reverse shell execution, file upload and download, and remote desktop-style control.
That turns an infected gaming PC into a surveillance and control point. The risk becomes especially serious when the victim is a younger player, a streamer, or someone who uses the same device for school, payments, crypto wallets, or family accounts.
McAfee Labs also warned that WeedHack has been used for cyberbullying and harassment. Researchers observed customers using remote-access features to monitor victims, threaten them, and share compromising content in criminal communities.
- Webcam access can expose victims in private settings.
- Keylogging can capture passwords and private messages.
- Screen sharing can reveal accounts, chats, payment details, and personal files.
- Remote shell access can let attackers run additional commands.
- File upload and download features can support further malware deployment or data theft.
Why Minecraft players are easy targets for malware services
Minecraft has a large modding culture, and many players regularly download third-party tools to change gameplay, improve performance, or join specific communities. Attackers exploit that trust by copying the look of legitimate mod pages and using names that players already recognize.
The risk increases when younger users follow YouTube tutorials or Discord posts without checking the source. A polished video, a fake download button, and a familiar mod name can make a malicious file look safe.
The official Minecraft Marketplace safety guidance reminds players to use safe and trusted sources for content. That advice matters even more when malware campaigns abuse unofficial downloads and third-party mod sites.
| Risky behavior | Safer approach |
|---|---|
| Downloading mods from video descriptions | Use trusted mod platforms and verify the creator |
| Running random JAR files | Scan files and inspect the source before opening |
| Trusting fake client websites | Check official project pages and community reputation |
| Using the same browser profile for gaming and finance | Separate sensitive accounts from risky downloads |
| Ignoring antivirus or Defender warnings | Stop the install and investigate the file |
Security teams should look beyond static signatures
WeedHack uses staged payloads, obfuscation, Ethereum-based infrastructure discovery, and customer-built malware variants. That means hash-based detection alone will miss parts of the ecosystem as new JAR files and distribution pages appear.
Defenders should combine endpoint behavior, network activity, browser credential access, suspicious Java execution, and known infrastructure indicators. Parent-child process relationships can also help, especially when javaw.exe launches unusual payloads, disables security controls, or contacts unfamiliar endpoints after a Minecraft-related download.
The Hacker News coverage notes that the WeedHack dashboard lets customers build payloads targeting Minecraft versions 1.21.0 through 1.21.11 and inject malware into legitimate Minecraft mods. That flexibility makes ongoing detection and user education important.
- Monitor Java and javaw.exe launching from download folders or temporary directories.
- Alert when Minecraft-related JAR files modify Microsoft Defender settings.
- Watch for browser credential database access after a mod install.
- Inspect outbound traffic to unusual command-and-control domains or blockchain-related infrastructure.
- Search for known WeedHack hashes and related files in endpoint telemetry.
- Use MalwareBazaar WeedHack samples as hunting leads, but do not rely only on hashes.
How players and parents can reduce the risk
Players should treat any Minecraft mod, cheat, hacked client, or custom launcher as executable software. If the file comes from a YouTube description, a random Discord post, a search ad, or a newly created download site, it should be considered high risk.
Parents should also talk to younger players about why free cheats and clients can be dangerous. The threat is not only stolen game accounts. WeedHack can expose private photos, webcam feeds, chat messages, passwords, and payment-related data.
Players should use official stores, trusted community platforms, and clear safety rules for downloads. The Minecraft safety page is a useful baseline for explaining safer content choices to younger users.
- Download mods only from trusted sources with a known reputation.
- Avoid Minecraft cheats, cracked clients, and files promoted through suspicious videos.
- Do not run JAR files from unknown websites.
- Keep Microsoft Defender or another reputable security tool enabled.
- Use separate passwords for Minecraft, Microsoft, Discord, Steam, and email accounts.
- Enable multi-factor authentication where available.
- Reinstall the operating system or seek expert help if webcam access, password theft, or remote control is suspected.
WeedHack shows how gaming malware has moved from simple account theft to a commercial service model with dashboards, subscriptions, tutorials, and remote-access tools. Minecraft players should treat unofficial mod downloads with the same caution they would apply to any other executable file.
FAQ
WeedHack is a Minecraft-focused malware-as-a-service operation that spreads through fake mods, hacked clients, YouTube videos, search engine poisoning, and fake download sites. It can steal credentials, cookies, Discord tokens, Steam data, cryptocurrency wallets, and Minecraft session information.
Victims usually download a malicious Java Archive file that is presented as a Minecraft mod, client, or cheat. When the JAR file runs, it starts a staged infection chain that can disable security controls, steal data, and install remote-access components.
WeedHack can steal browser passwords and cookies, Minecraft session IDs, Discord tokens, Steam credentials, Telegram data, cryptocurrency wallet data, screenshots, system information, and files from infected devices.
Yes. Researchers say WeedHack’s paid tier includes remote-access features such as webcam access, keylogging, screen sharing, file transfer, and reverse shell execution.
Players should avoid unofficial cheats and hacked clients, download mods only from trusted sources, scan files before opening them, keep security tools enabled, use unique passwords, and enable multi-factor authentication on important accounts.
Read our disclosure page to find out how can you help VPNCentral sustain the editorial team Read more
User forum
0 messages