Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

US Sanctions Mabna Institute Hackers for Iranian Cyber-Attacks

August 26, 2026

StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data

August 26, 2026

Fake Minecraft Clients Deliver WeedHack Malware Despite Takedown

August 25, 2026
Facebook X (Twitter) Instagram
Wednesday, August 26
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Fake Minecraft Clients Deliver WeedHack Malware Despite Takedown
News

Fake Minecraft Clients Deliver WeedHack Malware Despite Takedown

Team-CWDBy Team-CWDAugust 25, 2026No Comments2 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


A large-scale malware-spreading scheme targeting Minecraft players has continued to evolve despite the takedown of the threat actor’s malicious infrastructure in July.

In a new report, researchers at McAfee shared that over 6300 attempts to access malicious sites linked to the ‘WeedHack’ malware campaign were blocked by McAfee WebAdvisor in the past month.

WeedHack is a malware-as-a-service (MaaS) campaign spotted by McAfeee in July.

It utilized SEO poisoning techniques and malicious websites impersonating legitimate Minecraft clients and infected over 116,464 gamers with malware.

While the initial infrastructure underlying the campaign, including the command-and-control (C2) server, was taken down by McAfee in July, the researchers noticed that the campaign was still active in August.

“Consequently, we have observed a shift in tactics by these attackers,” McAfee researchers said, noting that threat actors have increasingly pivoted to file-hosting services such as Discord to distribute WeedHack.

Discord accounted for 49.6% of the links associated with WeedHack deployments identified by the cybersecurity firm, followed by MediaFire (23.4%), GitHub (8.2%), and Dropbox (4.6%).

The remaining URLs were customer-facing websites impersonating Minecraft resellers, sometimes offering paid tools for free to lure users into clicking on malicious links. 

“In one case, the top two Google results observed by researchers for a popular Minecraft client led to sites distributing WeedHack, demonstrating how SEO poisoning can put malicious downloads directly in gamers’ paths,” the researchers wrote.

Researchers also identified a malicious site built using an AI-powered website creation platform.

To avoid falling into the trap the threat actor has set up for them, McAfee researchers recommended that gamers download mods, clients and other files only from trusted, official sources, while avoiding suspicious offers such as free versions of paid tools or cracked software.

They also advised keeping security software enabled, scanning downloads before opening them and checking URLs carefully for lookalike domains that could lead to malicious sites.

Image credits: Mehaniq / Shutterstock.com



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleCritical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation
Next Article StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data
Team-CWD
  • Website

Related Posts

News

US Sanctions Mabna Institute Hackers for Iranian Cyber-Attacks

August 26, 2026
News

StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data

August 26, 2026
News

Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation

August 25, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

All Major LLMs Exposed to Multi-Turn Manipulation, Warn Researchers

May 27, 20269 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

Common Apple Pay scams, and how to stay safe

January 22, 2026

How to tell if a voice call is AI or not

February 23, 2026

Why the tech industry needs to stand firm on preserving end-to-end encryption

September 12, 2025

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.