WeedHack Resurfaces via Fake Minecraft Clients and SEO Poisoning

Amber | Attack
TA2026248 | WeedHack Resurfaces via Fake Minecraft Clients and SEO Poisoning

WeedHack Resurfaces via Fake Minecraft Clients and SEO Poisoning

WeedHack is a malware sold as a Malware-as-a-Service (MaaS) offering that preys on Minecraft players. After disrupting the campaign's command-and-control (C2) server, it was discovered that the operators shifted tactics and kept the malware in circulation through lookalike Minecraft client websites, SEO poisoning, abused file-hosting services, and trusted community platforms. Victims are tricked into downloading WeedHack-laced JAR files that pose as legitimate clients or mods, after which the malware profiles the host, weakens Microsoft Defender, and steals credentials, browser data, session cookies, and cryptocurrency wallet contents.


WeedHack Resurfaces via Fake Minecraft Clients and SEO Poisoning: Attack Details

1

Over 116,000 Infections Since a Survived Takedown

WeedHack first came to light in June 2026, a Minecraft-focused Malware-as-a-Service operation that had been running since January of that year. By the time it was discovered, the campaign had logged over 116,464 infections and was adding between 2,000 and 3,000 new victims every day. It operated through a clear-net dashboard accessible to anyone with a Discord account, offering a free infostealer tier and a premium remote-access package starting at $5 per month, with a customer-facing Telegram channel of over 850 members. The initial investigation disrupted the campaign's command-and-control infrastructure; however, the August 2026 follow-up found that the distribution network had survived the takedown intact, and more than ten fake Minecraft client sites were still actively spreading WeedHack payloads.

2

SEO Poisoning Outranks the Real Minecraft Clients

WeedHack reaches its victims almost entirely through deception rather than exploitation. The operators lean heavily on SEO poisoning, crafting fake websites that outrank the genuine projects across Google, Microsoft Bing, Brave Search, and DuckDuckGo. In one telling case, the top two search results for a popular client named Xenon Client pointed straight to malicious lookalike sites. These pages are painstakingly built to mirror the real thing, copying feature lists, FAQs, installation guides, developer credits, and even links to authentic GitHub repositories so a casual visitor has little reason to doubt them. The lure is usually a free or "cracked" version of a paid tool, and the payload arrives as a JAR file. Distribution is spread across channels players already trust: nearly half of the malicious links were on Discord (49.6%), followed by MediaFire (23.4%), GitHub (8.2%), and Dropbox (4.6%), with additional payloads planted on legitimate community platforms such as Planet Minecraft and EndMods. One fake site was even assembled with the AI website builder lovable.app, showing how cheaply attackers can now stand up convincing new domains.

3

Defender Exclusions Clear the Way for the Payload

Once a victim runs the malicious JAR, WeedHack begins a multi-stage sequence that ends in the deployment of its infostealer payload. Early in that chain the malware profiles the machine by collecting system information, then quietly reduces the host's defenses by setting up Microsoft Defender exclusions so its components can run without interruption. Several of the distribution sites reinforce this by instructing users to disable their antivirus before installation, framing the request as a normal step for running a cheat or client.

4

Credentials, Sessions and Wallets, Monitored Live

Because WeedHack targets individual gamers rather than enterprise networks, the sources describe credential and data theft rather than traditional lateral movement across a network. The malware harvests passwords and browser data, lifts active session cookies, and pulls sensitive information directly from the compromised host, giving operators immediate access to the victim's accounts without needing to move deeper into any infrastructure. Stolen data is funneled back to the operators, who in the paid tier of the service could monitor victims in real time through a dashboard that displayed captured credentials and allowed custom payloads to be configured; the premium tier also advertised webcam surveillance. The earlier documented variant maintained resilient contact with its infrastructure using EtherHiding, a technique that fetches the attacker's active server address from the Ethereum blockchain so the malware can keep reaching a live C2 even when individual servers are taken offline. Although the campaign's original C2 server has since been disrupted, the distribution network built around fake sites and file hosts remains active.


Mitigating the WeedHack Threat

1

Block the Identified WeedHack Infrastructure

Add the fake client domains, Discord invite links, and file-hosting URLs listed in the IoC section to web proxy, DNS, and endpoint blocklists so users cannot reach the active distribution points.

2

Hunt for Microsoft Defender Exclusion Tampering

Review endpoints for unexpected Defender exclusion entries, since WeedHack establishes these to evade detection. Treat newly added exclusions on user workstations as a strong investigative lead.

3

Detect and Quarantine Suspicious JAR Execution

Monitor for Java (JAR) files launched from browser download folders, Discord, or archive extractions on user machines, and flag those originating from Minecraft-client or "cracked tool" downloads for analysis.

4

Reset Credentials and Invalidate Sessions for Affected Users

For any host confirmed or suspected to have run WeedHack, rotate passwords, revoke active session tokens, and force re-authentication, as the malware steals stored passwords and live session cookies.

5

Protect Cryptocurrency Wallets on Impacted Hosts

Where wallet software or browser wallet extensions were present on an infected machine, move funds to a clean device and rotate wallet credentials, given WeedHack's theft of wallet contents.

6

Prioritize Search-Result Verification

Reinforce that a top search-engine ranking does not equal legitimacy, since SEO poisoning deliberately pushes malicious lookalike sites above genuine sources. Encourage users to cross-check a project's real GitHub or Modrinth page before downloading.

7

Strengthen Endpoint Protection and Web Filtering

Ensure endpoint security and web-reputation tools are deployed, updated, and set to alert rather than silently allow, so malicious downloads are intercepted before execution and antivirus warnings are not casually dismissed.

8

Keep Systems and Software Updated

Maintain current operating system, browser, and security software patches on endpoints to reduce the attack surface available to opportunistic malware delivered through these channels.


Potential MITRE ATT&CK TTPs

T1583.001
Resource Development
Acquire Infrastructure — Domains
T1608.006
Resource Development
Stage Capabilities — SEO Poisoning
T1608.001
Resource Development
Stage Capabilities — Upload Malware
T1204.002
Execution
User Execution — Malicious File
T1562.001
Defense Evasion
Impair Defenses — Disable or Modify Tools
T1562.004
Defense Evasion
Impair Defenses — Disable or Modify System Firewall
T1036.005
Defense Evasion
Masquerading — Match Legitimate Name or Location
T1548.004
Defense Evasion
Abuse Elevation Control Mechanism — Elevated Execution with Prompt
T1027.002
Defense Evasion
Obfuscated Files or Information — Software Packing
T1684.001
Defense Evasion
Social Engineering — Impersonation
T1620
Defense Evasion
Reflective Code Loading
T1082
Discovery
System Information Discovery
T1005
Collection
Data from Local System
T1041
Exfiltration
Exfiltration Over C2 Channel
T1053.005
Persistence
Scheduled Task/Job — Scheduled Task
T1547.001
Persistence
Boot or Logon Autostart Execution — Registry Run Keys/Startup Folder
T1555.003
Credential Access
Credentials from Password Stores — Credentials from Web Browsers
T1539
Credential Access
Steal Web Session Cookie
T1528
Credential Access
Steal Application Access Token

Observed Indicators of Compromise

Type Value
SHA256 b982fbafa954a8dcf7cfcffe31bcf75a86b052b1f01cf535ffcafd2c48a56b60, 29546a03e07bfeb3025313b12671c758ced1c4921a4bc859a7ab40ec52584cdb, d81b98a69363d8d994ef553beeb5e15384ed32f0e343708b73c7e6b313b9aace, f790346bece8e448313f701586cc7fd18291dfda721aae8d86ebfacf14055645, 5f7680feccc15814299df3c3c11e9b1c4f33069aac5a19c03b87e15f30c2312b, 256b5b5d0524c442261028767b94f7188b0b81663b50c63300fca7733a04ea7d, e123d1f7cbea562237f7a5f50638d148fb58048c9ad095e0b0ad52e43bfedad0, d468983f98ff100ad8fd613315af4c88d67bec76782b66b260c413c587987bf0, ef31bb219b84744e02f90947f31a25958b2b34524ed3795799ed6eff876e4bcd, 5d537a058ec19e6ceea593738f122b777d866042ea0bad194539757de13c46f4, 697ee941abee202d8e84e5e3fed8b9f34eea8772ee56dc867fce017507a5eeaf, f9a6911e8d9130c779db2e79f901d75d90f9e3ad08c36e7fb927959b7d988bae, 86f8c0a92eb9aba3c3416667361652a9e11b6ddc1119bb5b3564bc107b950ddb, 790ff5cda1668e7aa390fbb1682a4d578195aa40542f64b7b6d56a6eccde12c9, db533717da686f3b76b9de85ecd80d326a14572056a33d31f794bffbffd96c26, 8b53f53f72b8fef755666b6f239c06a69a9940e1b9f5d19e022150750035fa80, 6b2218999ac27f6085cb02f693a3c99bd6abedfc20e00e22709e526015c89f4e, 9682adf40a3621ffe5e1b426c5b90d0ed70e663738857bb4d18d37d93bbd4e6c, f2100e1f73477bc565f8909e069942dac1f884654ed4ba213ca9a84b1e761ab8, d3f2464ae0e48218e1d48bdfab8301ee5236f7624adcdba1720dc27058461076, 3951533d56803cd5d708014b4eed7e30349b4c4ba43f7d843133b3a5e2992ce6, 37bcec9ba357a2cb13a4f0f910e40f01e33973a5d637a3487c298105ae1ff22b, 08a64523d7a05defb6cc5c87df340d76f9ef7ccc9623a0d338981be4cd9cd6c7, 36a89f65fe2d693a094b51495f3a84d0f4f2ae7276649952d6f78c85282e6f6d, d4918dbf7ada4883d89a01dcf5332413b7773b12d0e479f2cf502e3245c93720, cf9bc0a3e01a7b466bc35dbf88563adf61c884ad5fb2b28afd1298a5f723f370, d28bc760f0b80905ea199809ad7ebfc73ab12aeab0ad3ee2dd11990657d2d9eb, 7f69a67316872186fd440b4126a77c419f14b459542181c5e12feb49a223fd39, 902cb8bfa3863df299ac804dc77e3e9366658b2b3c2ec5d3a1bdaf2e52520ce5, 2a5baf86a3e982eb557dffffabb619c9e80581d41cdc4b85b06367b588647a7d, ea595940815a11901bd99214b26d9528034f7182bd6c3bf2fe3179ac92e00afc, dba9908f63f5f32405f7a728f37979e743814532378cabc4f0e9f24c34197c60, 77dd1dd9b12699c64ab31c0140b28c70339014a0969f3bb7a79068f5b8f3f34a, 32e743d1e3957f35651a9d15a83bc128b82108c17b0fa64d63fa98b1d326fc9d, a81ba29e550beae21fff69bfe0478249eb7078b173f9cf2040d74df299fc9d5b, 14118a6070f89baafd5f2aeaf2df7535a8053f99944453584f0d1efeb6501ac3, b9f71ed4b08c93a7fc5468bee23660e3129e1cf9c84100d4d40ad70fb7c851fa, 88d8ac22ea323842cd760d645daea54043739d45a0fa61fd72fe5a5c9acb5e69, fdceafe4dcf9cf6d23b2033824275c08ec73d6b01adc644416e43ecca94c89c9, 226889380ca1695158cd42ba4b7d89352c4fa74010583669ac89ad69fdefd566, 1b5ca4d2b5eb23041da0f6effdc408d50768701d4140a21c9fbd244f9458d720, c7691712d794d4ef582c591566bf5fda76a364b0bcdad315adbaaec8607ad0f3
Filename Glazed_Addon-1.0.0.jar, paper-rig-mod-new.jar, RadiumClient.jar, Radium-1.0.0 (1).jar, Bedrockfinder-1.0.0.jar, 4e client 1.21.11.jar, AutoRynek-1.21.4.jar, donutsmp-duper-1.0.0.jar, GodMode-2.8.1.jar, krypton-cracked-1.0.0.jar, krypton-cracked-1.0.01.jar, Example-1.0.0.jar, Krypton-1.0.0.jar, Vapev4-1.21.11.jar, Donutdupeworking-1.21.11.jar, opticam-1.0.0.jar, Nightsoulv2-1.21.11.jar, asdasd-1.21.111.jar, dupe_bypass_1.21.11-1.21.11.jar, elevator.jar, Module.jar, module.jar, SecurityManager.jar, component.jar, Telemetry.exe, RuntimeBroker.exe, WindowsRunetimeBroker.exe, elv.vbs, Updater.vbs, WinDefConfig.cmd, chromedriver.dll, fabric.api.json
File Path C:\Users\admin\AppData\Roaming\Microsoft\SecurityUpdates\SecurityManager.jar, C:\Users\admin\AppData\Roaming\Microsoft\SecurityUpdates\component.jar, C:\Users\admin\AppData\Roaming\ChromeDriver, C:\Users\admin\AppData\Roaming\RuntimeBroker.exe, C:\Users\admin\AppData\Roaming\Microsoft\Tlmtry, C:\Users\admin\AppData\Roaming\WindowsRunetimeBroker.exe
Domains weedhack[.]to, whpayment[.]ru, whack[.]cy, whtempdomain[.]com, whreceiverrrrrrrrr[.]ru, friendlydomain[.]ru, whrc[.]ru, whnewreceive[.]ru, weedhack[.]xyz, telemetrydata[.]to, acabstealer[.]ru, stealer[.]to, 1312services[.]ru, 1312stealer[.]ru, dieserbenni[.]ru, marsalek[.]cy, stealer[.]cy, newlumm[.]fun, limbo100x[.]ru, pentagon[.]cy
IPv4 92[.]119[.]164[.]235
URLs hxxps[:]//glazed-client[.]com/, hxxps[:]//github[.]com/Hl3n/GambleRigMod, hxxps[:]//www[.]radium-client[.]com/, hxxps[:]//discord[.]com/channels/1467145812906872834/, hxxps[:]//seedcrackerx[.]github[.]io/, hxxps[:]//github[.]com/seedcrackerx/seedcrackerx[.]github[.]io, hxxps[:]//xenonclient[.]com/, hxxps[:]//xenoclient[.]lol, hxxps[:]//nova-client[.]com/, hxxps[:]//cheatlib[.]xyz/, hxxps[:]//discord[.]com/channels/1478170973755936990, hxxps[:]//meteorclients[.]com, hxxp[:]//22qq-client[.]com/, hxxps[:]//kryptonclientcrack[.]lovable[.]app, hxxps[:]//github[.]com/lsellh/, hxxps[:]//static[.]planetminecraft[.]com/files/resource_media/mod/mousetweaks-fabric-mc1-21-9-2-29.jar, hxxps[:]//static[.]planetminecraft[.]com/files/resource_media/mod/no-delay-optimizer1-21-4.jar, hxxps[:]//endmods[.]com/wp-content/uploads/2026/02/KRYPTON-CLIENT1.0.zip, hxxps[:]//whpayment[.]ru, hxxp[:]//whack[.]cy/, hxxps[:]//weedhack[.]to/dashboard/auth/login, hxxps[:]//whtempdomain[.]com, hxxps[:]//whreceiverrrrrrrrr[.]ru/dashboard/overview, hxxp[:]//friendlydomain[.]ru/, hxxp[:]//whrc[.]ru/, hxxps[:]//whnewreceive[.]ru/, hxxp[:]//weedhack[.]xyz, hxxps[:]//aetherminecraft[.]lovable[.]app/game-mods, hxxps[:]//donutdupe[.]xyz/DonutDupe-1.21.1.jar, hxxps[:]//www[.]skytils[.]net/skytils-1.21.11.jar, hxxps[:]//night-client-Hub[.]lovable[.]app/downloads/dupeclient1.21.11-1.21.11.jar, hxxp[:]//chromium-Client[.]github[.]io/main/ChromiumClient-[.]jar, hxxps[:]//farmhelper-Macro[.]com/downloads/FarmHelper-1.21.jar, hxxps[:]//skyhanni[.]net/downloads/1-21-5/SkyHanni-6.0.0-mc1.21.5.jar, hxxps[:]//xenonclient[.]com/downloads/XenonClient-1.21.jar, hxxps[:]//odinclient[.]com/Odin-1.21.10-latest.jar, hxxps[:]//nova-client[.]com/Nova-Client-1.21.11-latest.jar, hxxps[:]//pixeldrain[.]com/api/file/o4jKp4Tx?download, hxxps[:]//kryptonclient[.]gg/downloads/KryptonClient.jar, hxxps[:]//simplevoicechatmod[.]com/downloads/voicechat-fabric-1.21.11-2.6.11.jar, hxxps[:]//www[.]notenoughupdates[.]net/downloads/NotEnoughUpdates-1.21.5.jar, hxxps[:]//t[.]me/+pw_g24ajDcQwMmYy, hxxps[:]//t[.]me/MetaMaskenMann, hxxp[:]//92[.]119[.]164[.]235/

References

The following sources detail the WeedHack activity described in this advisory.

What Next?

At Hive Pro, it is our mission to detect the most likely threats to your organization and to help you prevent them from happening.

Reduce real exposure. Not just vulnerability volume.