Threat Advisory

WeedHack Malware Spreads Using Fake Gaming Websites and Extracts Access Data

Threat: Malware Campaign
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

A malware campaign known as WeedHack is targeting Minecraft users by distributing malicious versions of popular gaming clients, mods, and tools through fake websites and manipulated search engine results. The campaign uses SEO poisoning techniques to place fraudulent gaming websites higher in search rankings, increasing the chances that users download infected files while searching for legitimate Minecraft enhancements. These deceptive websites imitate trusted projects by copying branding, features, documentation, and links to legitimate resources to appear authentic.[/subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

A malware campaign known as WeedHack is targeting Minecraft users by distributing malicious versions of popular gaming clients, mods, and tools through fake websites and manipulated search engine results. The campaign uses SEO poisoning techniques to place fraudulent gaming websites higher in search rankings, increasing the chances that users download infected files while searching for legitimate Minecraft enhancements. These deceptive websites imitate trusted projects by copying branding, features, documentation, and links to legitimate resources to appear authentic.[emaillocker id="1283"]

WeedHack spreads through counterfeit Minecraft client websites, file-hosting platforms, Discord links, and other community channels. Threat actors create lookalike domains that replicate legitimate gaming projects and distribute malicious JAR files containing the malware. The campaign abuses trusted platforms such as GitHub, MediaFire, and Discord to make downloads appear reliable. Attackers also leverage AI-powered website creation tools to quickly build convincing malicious pages and deploy additional infrastructure. The malware campaign follows a Malware-as-a-Service (MaaS) model, enabling users with limited technical knowledge to distribute infections and potentially access stolen data, credentials, and compromised systems.

It demonstrates how threat actors are increasingly targeting gaming communities through social engineering, fake software downloads, and search engine manipulation rather than relying only on traditional exploitation methods. Users should download Minecraft mods and clients only from verified sources, carefully inspect website domains, avoid suspicious free versions of paid tools, and scan downloaded files before execution to reduce the risk of malware infection.

 

THREAT PROFILE:

Tactic Technique Id Technique Sub-technique
Initial Access T1189 Drive-by Compromise
T1566.002 Phishing Spearphishing Link
Execution T1059.007 Command and Scripting Interpreter JavaScript
T1204.002 User Execution Malicious File
Persistence T1547.001 Boot or Logon Autostart Execution Registry Run Keys / Startup Folder
Stealth T1036.005 Masquerading Match Legitimate Resource Name or Location
T1027.013 Obfuscated Files or Information Encrypted/Encoded File
Credential Access T1555.003 Credentials from Password Stores Credentials from Web Browsers
Collection T1114.001 Email Collection Local Email Collection
Command and Control T1071.001 Application Layer Protocol Web Protocols

 

MBC MAPPING:

Objective Behavior ID Behavior
Command and Control B0030 C2 Communication
Discovery E1082 System Information Discovery
Execution E1204 User Execution
B0023 Install Additional Program

 

REFERENCES:

The following reports contain further technical details:

https://www.mcafee.com/blogs/other-blogs/mcafee-labs/weedhack-minecraft-malware-fake-gaming-websites-seo-poisoning/

[/emaillocker]
crossmenu