EXECUTIVE SUMMARY:
A malware campaign known as WeedHack is targeting Minecraft users by distributing malicious versions of popular gaming clients, mods, and tools through fake websites and manipulated search engine results. The campaign uses SEO poisoning techniques to place fraudulent gaming websites higher in search rankings, increasing the chances that users download infected files while searching for legitimate Minecraft enhancements. These deceptive websites imitate trusted projects by copying branding, features, documentation, and links to legitimate resources to appear authentic.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
A malware campaign known as WeedHack is targeting Minecraft users by distributing malicious versions of popular gaming clients, mods, and tools through fake websites and manipulated search engine results. The campaign uses SEO poisoning techniques to place fraudulent gaming websites higher in search rankings, increasing the chances that users download infected files while searching for legitimate Minecraft enhancements. These deceptive websites imitate trusted projects by copying branding, features, documentation, and links to legitimate resources to appear authentic.[emaillocker id="1283"]
WeedHack spreads through counterfeit Minecraft client websites, file-hosting platforms, Discord links, and other community channels. Threat actors create lookalike domains that replicate legitimate gaming projects and distribute malicious JAR files containing the malware. The campaign abuses trusted platforms such as GitHub, MediaFire, and Discord to make downloads appear reliable. Attackers also leverage AI-powered website creation tools to quickly build convincing malicious pages and deploy additional infrastructure. The malware campaign follows a Malware-as-a-Service (MaaS) model, enabling users with limited technical knowledge to distribute infections and potentially access stolen data, credentials, and compromised systems.
It demonstrates how threat actors are increasingly targeting gaming communities through social engineering, fake software downloads, and search engine manipulation rather than relying only on traditional exploitation methods. Users should download Minecraft mods and clients only from verified sources, carefully inspect website domains, avoid suspicious free versions of paid tools, and scan downloaded files before execution to reduce the risk of malware infection.
THREAT PROFILE:
| Tactic | Technique Id | Technique | Sub-technique |
| Initial Access | T1189 | Drive-by Compromise | — |
| T1566.002 | Phishing | Spearphishing Link | |
| Execution | T1059.007 | Command and Scripting Interpreter | JavaScript |
| T1204.002 | User Execution | Malicious File | |
| Persistence | T1547.001 | Boot or Logon Autostart Execution | Registry Run Keys / Startup Folder |
| Stealth | T1036.005 | Masquerading | Match Legitimate Resource Name or Location |
| T1027.013 | Obfuscated Files or Information | Encrypted/Encoded File | |
| Credential Access | T1555.003 | Credentials from Password Stores | Credentials from Web Browsers |
| Collection | T1114.001 | Email Collection | Local Email Collection |
| Command and Control | T1071.001 | Application Layer Protocol | Web Protocols |
MBC MAPPING:
| Objective | Behavior ID | Behavior |
| Command and Control | B0030 | C2 Communication |
| Discovery | E1082 | System Information Discovery |
| Execution | E1204 | User Execution |
| B0023 | Install Additional Program |
REFERENCES:
The following reports contain further technical details:
[/emaillocker]