Weedhack Malware Poses as Minecraft Clients
Fake Minecraft sites spread Weedhack malware via SEO poisoning, with thousands of blocked attempts reported.
Gamers hunting for Minecraft clients are walking into a trap. Researchers at McAfee Labs have uncovered an active campaign where malicious websites mimic legitimate Minecraft tools, distributing a malware family known as Weedhack. The fake sites are polished enough to fool even savvy users, and the campaign is using search engine optimization to push them to the top of results.
SEO Poisoning at Play
McAfee Labs reported that it detected and blocked more than 6,300 attempts to access these malicious sites. The lookalike websites are designed to imitate genuine projects, complete with branding, feature lists, FAQs, installation guides, developer credits, and even links to real GitHub repositories. This level of detail makes them hard to distinguish from the real thing.
One of the sites was built using Lovable, an AI-powered website builder, according to the researchers. This shows how readily available tools can lower the barrier for attackers, making it easier to launch convincing new malicious sites. The use of AI to craft fake sites is a worrying development, as it allows for rapid creation of believable scams.
Nearly half of the malicious URLs identified were Discord links (49.6%), followed by MediaFire (23.4%) and GitHub (8.2%), showing how attackers can use familiar platforms alongside fake websites to distribute malware.
This statement comes from McAfee Labs researcher Aayush Tyagi, who highlighted the varied distribution methods used in the campaign.
Fake Domains List
The researchers identified several fake domains that are actively distributing the malware. These include glazed-client[.]com, which replicates the legitimate open-source Minecraft add-on of the same name, and radium-client[.]com, which imitates a paid Minecraft client. Another example is seedcrackerx.github[.]io, which mimics seedcrackerx[.]com, a Minecraft seed cracking software.
Other fake sites include cheatlib[.]xyz, which claims to be a "modern Minecraft mod library" with over 1.6 million downloads, and meteorclients[.]com, which replicates the well-known meteor client. The list goes on with 22qq-client[.]com, impersonating a mod for Crystal PvP servers, and kryptonclientcrack.lovable[.]app, which replicates a paid tool for the DonutSMP server. Nova-client[.]com and xenoclient[.]lol round out the list, impersonating popular open-source clients.
Outranking Legitimate Sources
The attackers are using SEO poisoning to outrank the official sources in search results. In fact, both the websites for Xenon Client and Nova Client appear at the top of search results across search engines like Google, Microsoft Bing, Brave Search, and DuckDuckGo. This means unsuspecting users who search for these clients are likely to click on the malicious links first.
"The legitimate client is hosted on GitHub and Modrinth; however, attackers have created a spoofed website and leveraged SEO poisoning techniques to outrank the official sources in search results," McAfee Labs stated in their analysis. This tactic is particularly effective because users often trust search results, assuming that top links are safe.
Multi-Stage Attack Sequence
The Weedhack malware was first documented by McAfee Labs in June 2026. The attack triggers a multi-stage sequence that culminates in the deployment of JAR payloads. These payloads can collect system information, set up Microsoft Defender exclusions, and steal sensitive data from the compromised host. This means the malware is not just a simple nuisance; it has the potential to hijack a user's system and exfiltrate personal data.
The use of JAR files is common in Minecraft-related malware, as players are accustomed to installing Java-based mods and clients. This familiarity makes users more likely to execute the malicious files without suspicion.
Beyond Fake Websites
The distribution of Weedhack is not limited to fake websites. The researchers found that file hosting services and GitHub repositories are also being used to spread the malware. Links to these malicious files are distributed via Discord, Reddit, and other communication channels. Additionally, the JAR files are being hosted on legitimate Minecraft platforms like Planet Minecart and EndMods, which are trusted by the gaming community.
This multi-pronged approach increases the reach of the campaign, as attackers can target users through various entry points. The use of legitimate platforms as hosts also adds a layer of credibility, making it harder for users to identify the threat.
Protecting Yourself
To counter the threat, McAfee Labs advises keeping devices up-to-date, sticking to trusted sources, scanning files before opening them, and exercising caution when any mod or cheat prompts to disable security protections before installing it. These steps are crucial for gamers who frequently download third-party software.
It's also important to verify the authenticity of websites before downloading anything. Checking the URL for subtle differences, such as an extra hyphen or a different domain suffix, can help spot fakes. Users should also consider using ad-blockers and security software that can flag malicious sites.
This is not the first time SEO poisoning campaigns have been used to drop malware. In June 2026, Check Point flagged a large-scale operation that impersonated open-source and freeware projects. That campaign used a Traffic Distribution System (TDS) to funnel users into downloading malware families like Remus Stealer, AnimateClipper, and the SessionGate framework. This pattern indicates a growing trend where attackers leverage trusted names to distribute malware.
Why It Matters
The Weedhack campaign shows that even community-driven platforms like Minecraft are not immune to malware. The use of AI to build fake sites, combined with SEO poisoning, makes it increasingly difficult for users to tell real from fake. This could lead to a erosion of trust in search results, particularly for niche software.
For gamers, the stakes are high: downloading a fake client could result in data theft or system compromise. For the broader tech community, this serves as a reminder that cybercriminals are constantly adapting, using new tools and techniques to exploit users. It suggests that platform owners and search engines need to be more vigilant in identifying and removing malicious content, but until then, users must remain cautious and follow safety best practices.
Sources
- The Hacker News Original source
Continue Reading
AliExpress caught using inaudible audio to fingerprint browsers
Researcher discovers AliExpress using obsolete WebAudio fingerprinting; Firefox fix likely neutralizes it.
Limited Breach: ReliaQuest Confirms Hack
ReliaQuest says ShinyHunters accessed an identity dashboard briefly but no customer data was compromised.
NIST Flags Multi-Cloud Security Pitfalls
New NIST report outlines 23 unique challenges in multi-cloud environments, urging community-driven solutions.