Summary
WeedHack Resurfaces via Fake Minecraft Clients and SEO Poisoning
WeedHack is a malware sold as a Malware-as-a-Service (MaaS) offering that preys on Minecraft players. After disrupting the campaign's command-and-control (C2) server, it was discovered that the operators shifted tactics and kept the malware in circulation through lookalike Minecraft client websites, SEO poisoning, abused file-hosting services, and trusted community platforms. Victims are tricked into downloading WeedHack-laced JAR files that pose as legitimate clients or mods, after which the malware profiles the host, weakens Microsoft Defender, and steals credentials, browser data, session cookies, and cryptocurrency wallet contents.
Attack Details
WeedHack Resurfaces via Fake Minecraft Clients and SEO Poisoning: Attack Details
Over 116,000 Infections Since a Survived Takedown
WeedHack first came to light in June 2026, a Minecraft-focused Malware-as-a-Service operation that had been running since January of that year. By the time it was discovered, the campaign had logged over 116,464 infections and was adding between 2,000 and 3,000 new victims every day. It operated through a clear-net dashboard accessible to anyone with a Discord account, offering a free infostealer tier and a premium remote-access package starting at $5 per month, with a customer-facing Telegram channel of over 850 members. The initial investigation disrupted the campaign's command-and-control infrastructure; however, the August 2026 follow-up found that the distribution network had survived the takedown intact, and more than ten fake Minecraft client sites were still actively spreading WeedHack payloads.
SEO Poisoning Outranks the Real Minecraft Clients
WeedHack reaches its victims almost entirely through deception rather than exploitation. The operators lean heavily on SEO poisoning, crafting fake websites that outrank the genuine projects across Google, Microsoft Bing, Brave Search, and DuckDuckGo. In one telling case, the top two search results for a popular client named Xenon Client pointed straight to malicious lookalike sites. These pages are painstakingly built to mirror the real thing, copying feature lists, FAQs, installation guides, developer credits, and even links to authentic GitHub repositories so a casual visitor has little reason to doubt them. The lure is usually a free or "cracked" version of a paid tool, and the payload arrives as a JAR file. Distribution is spread across channels players already trust: nearly half of the malicious links were on Discord (49.6%), followed by MediaFire (23.4%), GitHub (8.2%), and Dropbox (4.6%), with additional payloads planted on legitimate community platforms such as Planet Minecraft and EndMods. One fake site was even assembled with the AI website builder lovable.app, showing how cheaply attackers can now stand up convincing new domains.
Defender Exclusions Clear the Way for the Payload
Once a victim runs the malicious JAR, WeedHack begins a multi-stage sequence that ends in the deployment of its infostealer payload. Early in that chain the malware profiles the machine by collecting system information, then quietly reduces the host's defenses by setting up Microsoft Defender exclusions so its components can run without interruption. Several of the distribution sites reinforce this by instructing users to disable their antivirus before installation, framing the request as a normal step for running a cheat or client.
Credentials, Sessions and Wallets, Monitored Live
Because WeedHack targets individual gamers rather than enterprise networks, the sources describe credential and data theft rather than traditional lateral movement across a network. The malware harvests passwords and browser data, lifts active session cookies, and pulls sensitive information directly from the compromised host, giving operators immediate access to the victim's accounts without needing to move deeper into any infrastructure. Stolen data is funneled back to the operators, who in the paid tier of the service could monitor victims in real time through a dashboard that displayed captured credentials and allowed custom payloads to be configured; the premium tier also advertised webcam surveillance. The earlier documented variant maintained resilient contact with its infrastructure using EtherHiding, a technique that fetches the attacker's active server address from the Ethereum blockchain so the malware can keep reaching a live C2 even when individual servers are taken offline. Although the campaign's original C2 server has since been disrupted, the distribution network built around fake sites and file hosts remains active.
Recommendations
Mitigating the WeedHack Threat
Block the Identified WeedHack Infrastructure
Add the fake client domains, Discord invite links, and file-hosting URLs listed in the IoC section to web proxy, DNS, and endpoint blocklists so users cannot reach the active distribution points.
Hunt for Microsoft Defender Exclusion Tampering
Review endpoints for unexpected Defender exclusion entries, since WeedHack establishes these to evade detection. Treat newly added exclusions on user workstations as a strong investigative lead.
Detect and Quarantine Suspicious JAR Execution
Monitor for Java (JAR) files launched from browser download folders, Discord, or archive extractions on user machines, and flag those originating from Minecraft-client or "cracked tool" downloads for analysis.
Reset Credentials and Invalidate Sessions for Affected Users
For any host confirmed or suspected to have run WeedHack, rotate passwords, revoke active session tokens, and force re-authentication, as the malware steals stored passwords and live session cookies.
Protect Cryptocurrency Wallets on Impacted Hosts
Where wallet software or browser wallet extensions were present on an infected machine, move funds to a clean device and rotate wallet credentials, given WeedHack's theft of wallet contents.
Prioritize Search-Result Verification
Reinforce that a top search-engine ranking does not equal legitimacy, since SEO poisoning deliberately pushes malicious lookalike sites above genuine sources. Encourage users to cross-check a project's real GitHub or Modrinth page before downloading.
Strengthen Endpoint Protection and Web Filtering
Ensure endpoint security and web-reputation tools are deployed, updated, and set to alert rather than silently allow, so malicious downloads are intercepted before execution and antivirus warnings are not casually dismissed.
Keep Systems and Software Updated
Maintain current operating system, browser, and security software patches on endpoints to reduce the attack surface available to opportunistic malware delivered through these channels.
MITRE ATT&CK TTPs
Potential MITRE ATT&CK TTPs
Indicators of Compromise (IoCs)
Observed Indicators of Compromise
| Type | Value |
|---|---|
| SHA256 | b982fbafa954a8dcf7cfcffe31bcf75a86b052b1f01cf535ffcafd2c48a56b60, 29546a03e07bfeb3025313b12671c758ced1c4921a4bc859a7ab40ec52584cdb, d81b98a69363d8d994ef553beeb5e15384ed32f0e343708b73c7e6b313b9aace, f790346bece8e448313f701586cc7fd18291dfda721aae8d86ebfacf14055645, 5f7680feccc15814299df3c3c11e9b1c4f33069aac5a19c03b87e15f30c2312b, 256b5b5d0524c442261028767b94f7188b0b81663b50c63300fca7733a04ea7d, e123d1f7cbea562237f7a5f50638d148fb58048c9ad095e0b0ad52e43bfedad0, d468983f98ff100ad8fd613315af4c88d67bec76782b66b260c413c587987bf0, ef31bb219b84744e02f90947f31a25958b2b34524ed3795799ed6eff876e4bcd, 5d537a058ec19e6ceea593738f122b777d866042ea0bad194539757de13c46f4, 697ee941abee202d8e84e5e3fed8b9f34eea8772ee56dc867fce017507a5eeaf, f9a6911e8d9130c779db2e79f901d75d90f9e3ad08c36e7fb927959b7d988bae, 86f8c0a92eb9aba3c3416667361652a9e11b6ddc1119bb5b3564bc107b950ddb, 790ff5cda1668e7aa390fbb1682a4d578195aa40542f64b7b6d56a6eccde12c9, db533717da686f3b76b9de85ecd80d326a14572056a33d31f794bffbffd96c26, 8b53f53f72b8fef755666b6f239c06a69a9940e1b9f5d19e022150750035fa80, 6b2218999ac27f6085cb02f693a3c99bd6abedfc20e00e22709e526015c89f4e, 9682adf40a3621ffe5e1b426c5b90d0ed70e663738857bb4d18d37d93bbd4e6c, f2100e1f73477bc565f8909e069942dac1f884654ed4ba213ca9a84b1e761ab8, d3f2464ae0e48218e1d48bdfab8301ee5236f7624adcdba1720dc27058461076, 3951533d56803cd5d708014b4eed7e30349b4c4ba43f7d843133b3a5e2992ce6, 37bcec9ba357a2cb13a4f0f910e40f01e33973a5d637a3487c298105ae1ff22b, 08a64523d7a05defb6cc5c87df340d76f9ef7ccc9623a0d338981be4cd9cd6c7, 36a89f65fe2d693a094b51495f3a84d0f4f2ae7276649952d6f78c85282e6f6d, d4918dbf7ada4883d89a01dcf5332413b7773b12d0e479f2cf502e3245c93720, cf9bc0a3e01a7b466bc35dbf88563adf61c884ad5fb2b28afd1298a5f723f370, d28bc760f0b80905ea199809ad7ebfc73ab12aeab0ad3ee2dd11990657d2d9eb, 7f69a67316872186fd440b4126a77c419f14b459542181c5e12feb49a223fd39, 902cb8bfa3863df299ac804dc77e3e9366658b2b3c2ec5d3a1bdaf2e52520ce5, 2a5baf86a3e982eb557dffffabb619c9e80581d41cdc4b85b06367b588647a7d, ea595940815a11901bd99214b26d9528034f7182bd6c3bf2fe3179ac92e00afc, dba9908f63f5f32405f7a728f37979e743814532378cabc4f0e9f24c34197c60, 77dd1dd9b12699c64ab31c0140b28c70339014a0969f3bb7a79068f5b8f3f34a, 32e743d1e3957f35651a9d15a83bc128b82108c17b0fa64d63fa98b1d326fc9d, a81ba29e550beae21fff69bfe0478249eb7078b173f9cf2040d74df299fc9d5b, 14118a6070f89baafd5f2aeaf2df7535a8053f99944453584f0d1efeb6501ac3, b9f71ed4b08c93a7fc5468bee23660e3129e1cf9c84100d4d40ad70fb7c851fa, 88d8ac22ea323842cd760d645daea54043739d45a0fa61fd72fe5a5c9acb5e69, fdceafe4dcf9cf6d23b2033824275c08ec73d6b01adc644416e43ecca94c89c9, 226889380ca1695158cd42ba4b7d89352c4fa74010583669ac89ad69fdefd566, 1b5ca4d2b5eb23041da0f6effdc408d50768701d4140a21c9fbd244f9458d720, c7691712d794d4ef582c591566bf5fda76a364b0bcdad315adbaaec8607ad0f3 |
| Filename | Glazed_Addon-1.0.0.jar, paper-rig-mod-new.jar, RadiumClient.jar, Radium-1.0.0 (1).jar, Bedrockfinder-1.0.0.jar, 4e client 1.21.11.jar, AutoRynek-1.21.4.jar, donutsmp-duper-1.0.0.jar, GodMode-2.8.1.jar, krypton-cracked-1.0.0.jar, krypton-cracked-1.0.01.jar, Example-1.0.0.jar, Krypton-1.0.0.jar, Vapev4-1.21.11.jar, Donutdupeworking-1.21.11.jar, opticam-1.0.0.jar, Nightsoulv2-1.21.11.jar, asdasd-1.21.111.jar, dupe_bypass_1.21.11-1.21.11.jar, elevator.jar, Module.jar, module.jar, SecurityManager.jar, component.jar, Telemetry.exe, RuntimeBroker.exe, WindowsRunetimeBroker.exe, elv.vbs, Updater.vbs, WinDefConfig.cmd, chromedriver.dll, fabric.api.json |
| File Path | C:\Users\admin\AppData\Roaming\Microsoft\SecurityUpdates\SecurityManager.jar, C:\Users\admin\AppData\Roaming\Microsoft\SecurityUpdates\component.jar, C:\Users\admin\AppData\Roaming\ChromeDriver, C:\Users\admin\AppData\Roaming\RuntimeBroker.exe, C:\Users\admin\AppData\Roaming\Microsoft\Tlmtry, C:\Users\admin\AppData\Roaming\WindowsRunetimeBroker.exe |
| Domains | weedhack[.]to, whpayment[.]ru, whack[.]cy, whtempdomain[.]com, whreceiverrrrrrrrr[.]ru, friendlydomain[.]ru, whrc[.]ru, whnewreceive[.]ru, weedhack[.]xyz, telemetrydata[.]to, acabstealer[.]ru, stealer[.]to, 1312services[.]ru, 1312stealer[.]ru, dieserbenni[.]ru, marsalek[.]cy, stealer[.]cy, newlumm[.]fun, limbo100x[.]ru, pentagon[.]cy |
| IPv4 | 92[.]119[.]164[.]235 |
| URLs | hxxps[:]//glazed-client[.]com/, hxxps[:]//github[.]com/Hl3n/GambleRigMod, hxxps[:]//www[.]radium-client[.]com/, hxxps[:]//discord[.]com/channels/1467145812906872834/, hxxps[:]//seedcrackerx[.]github[.]io/, hxxps[:]//github[.]com/seedcrackerx/seedcrackerx[.]github[.]io, hxxps[:]//xenonclient[.]com/, hxxps[:]//xenoclient[.]lol, hxxps[:]//nova-client[.]com/, hxxps[:]//cheatlib[.]xyz/, hxxps[:]//discord[.]com/channels/1478170973755936990, hxxps[:]//meteorclients[.]com, hxxp[:]//22qq-client[.]com/, hxxps[:]//kryptonclientcrack[.]lovable[.]app, hxxps[:]//github[.]com/lsellh/, hxxps[:]//static[.]planetminecraft[.]com/files/resource_media/mod/mousetweaks-fabric-mc1-21-9-2-29.jar, hxxps[:]//static[.]planetminecraft[.]com/files/resource_media/mod/no-delay-optimizer1-21-4.jar, hxxps[:]//endmods[.]com/wp-content/uploads/2026/02/KRYPTON-CLIENT1.0.zip, hxxps[:]//whpayment[.]ru, hxxp[:]//whack[.]cy/, hxxps[:]//weedhack[.]to/dashboard/auth/login, hxxps[:]//whtempdomain[.]com, hxxps[:]//whreceiverrrrrrrrr[.]ru/dashboard/overview, hxxp[:]//friendlydomain[.]ru/, hxxp[:]//whrc[.]ru/, hxxps[:]//whnewreceive[.]ru/, hxxp[:]//weedhack[.]xyz, hxxps[:]//aetherminecraft[.]lovable[.]app/game-mods, hxxps[:]//donutdupe[.]xyz/DonutDupe-1.21.1.jar, hxxps[:]//www[.]skytils[.]net/skytils-1.21.11.jar, hxxps[:]//night-client-Hub[.]lovable[.]app/downloads/dupeclient1.21.11-1.21.11.jar, hxxp[:]//chromium-Client[.]github[.]io/main/ChromiumClient-[.]jar, hxxps[:]//farmhelper-Macro[.]com/downloads/FarmHelper-1.21.jar, hxxps[:]//skyhanni[.]net/downloads/1-21-5/SkyHanni-6.0.0-mc1.21.5.jar, hxxps[:]//xenonclient[.]com/downloads/XenonClient-1.21.jar, hxxps[:]//odinclient[.]com/Odin-1.21.10-latest.jar, hxxps[:]//nova-client[.]com/Nova-Client-1.21.11-latest.jar, hxxps[:]//pixeldrain[.]com/api/file/o4jKp4Tx?download, hxxps[:]//kryptonclient[.]gg/downloads/KryptonClient.jar, hxxps[:]//simplevoicechatmod[.]com/downloads/voicechat-fabric-1.21.11-2.6.11.jar, hxxps[:]//www[.]notenoughupdates[.]net/downloads/NotEnoughUpdates-1.21.5.jar, hxxps[:]//t[.]me/+pw_g24ajDcQwMmYy, hxxps[:]//t[.]me/MetaMaskenMann, hxxp[:]//92[.]119[.]164[.]235/ |
References & Patch Links
References
The following sources detail the WeedHack activity described in this advisory.
- https://www.mcafee.com/blogs/other-blogs/mcafee-labs/weedhack-minecraft-malware-fake-gaming-websites-seo-poisoning/
- https://www.mcafee.com/blogs/other-blogs/mcafee-labs/weedhack-minecraft-malware-as-a-service-campaign-research/
What Next?
At Hive Pro, it is our mission to detect the most likely threats to your organization and to help you prevent them from happening.
