A widespread malware campaign targeting Minecraft players, dubbed "WeedHack," has continued to evolve and spread despite the takedown of its initial infrastructure in July. Cybersecurity researchers reported that over 6,300 attempts to access malicious sites associated with WeedHack were blocked in the past month, indicating ongoing activity.
The WeedHack campaign, first identified in July, utilizes SEO poisoning techniques to direct users to malicious websites impersonating legitimate Minecraft clients. These sites then deliver the WeedHack malware. The initial campaign reportedly infected over 116,464 gamers.
Following the July takedown of the campaign's original command-and-control (C2) server and other infrastructure, threat actors shifted their distribution tactics. They are now increasingly leveraging file-hosting services to spread WeedHack. Discord accounts for nearly half (49.6%) of the identified malicious links, followed by MediaFire (23.4%), GitHub (8.2%), and Dropbox (4.6%). The remaining URLs lead to fake Minecraft reseller websites, some of which offer paid tools for free to entice users.
Researchers observed instances where the top two Google search results for a popular Minecraft client led directly to sites distributing WeedHack, highlighting the effectiveness of the SEO poisoning. In one case, a malicious site was found to have been built using an AI-powered website creation platform.
To mitigate the risk of infection, security experts advise gamers to download mods, clients, and other files exclusively from trusted, official sources. They also recommend avoiding suspicious offers, such as free versions of paid software or cracked programs. Users should maintain active security software, scan all downloads before opening them, and carefully inspect URLs for lookalike domains that could lead to malicious sites.






