Disrupting WeedHack’s command-and-control infrastructure did not stop its distribution. Fake Minecraft client sites and trusted hosting services continued serving the malware after the original backend was taken down.
McAfee’s Aug. 20 follow-up found more than 6,300 attempts to reach malicious WeedHack sites during a one-month observation period. ThaiCERT followed with an Aug. 26 warning about the same campaign, which uses SEO poisoning and cloned project pages to steer users toward malicious JAR files.
McAfee’s June 2 investigation first documented WeedHack as a malware-as-a-service (MaaS) operation with more than 3,820 malicious JAR files across 240 distribution URLs. The operation delivers credential-stealing and remote-access malware through fake Minecraft mods, clients, and other downloads.
Fake Minecraft sites continue distributing WeedHack
By the time of McAfee’s Aug. 20 follow-up, WeedHack’s original C2 infrastructure and malware dashboard were no longer active. McAfee said the campaign had been disrupted, but researchers still found active websites serving malicious JAR files. The research does not establish exactly when the C2 infrastructure stopped operating.
ThaiCERT’s Aug. 26 warning separately urged users not to trust search rankings alone when downloading Minecraft add-ons or clients.
SEO poisoning is a central delivery method. The top two Google results McAfee observed for Xenon Client led to sites distributing WeedHack, while other malicious sites copied legitimate projects’ branding, installation instructions, FAQs, developer information, and links to genuine GitHub repositories.
Attackers also relied on legitimate platforms. Among malicious URLs examined, 49.6% were Discord links, 23.4% MediaFire, 8.2% GitHub, and 4.6% Dropbox. Similar trust abuse appeared in an August RMM phishing campaign spanning 46 countries, where attackers used legitimate remote-access software to blend malicious activity into normal IT workflows.
McAfee found WeedHack can steal Minecraft session IDs, browser passwords and cookies, messaging and gaming credentials, cryptocurrency-wallet data, screenshots, and system information. Its premium tier, advertised from $5 per month, adds webcam access, keylogging, reverse-shell execution, screen control, and file-management capabilities.
WeedHack also uses EtherHiding to retrieve its latest C2 domain through an Ethereum smart contract. McAfee observed later stages adding Defender exclusions, scheduled tasks, registry persistence, and remote-access components. Rotating infrastructure has appeared in other infostealer campaigns; Microsoft recently linked more than 30 domains to MacSync Stealer by correlating endpoint and network behavior instead of relying on domains alone.
Layered defenses target WeedHack’s attack chain
Defenses should cover execution control, endpoint behavior, identity exposure, and response readiness rather than rely only on known-domain blocklists.
- Restrict unapproved JAR execution. Use application control or allowlisting to block unauthorized Java archives in user-writable locations.
- Limit unnecessary Java and software. Remove unused runtimes and prevent unapproved game clients or mods on managed systems.
- Strengthen web and download filtering. Apply reputation checks, sandboxing, and file controls to suspicious downloads from legitimate hosting services.
- Monitor endpoint changes. Hunt for unusual Java activity, Defender exclusions, scheduled tasks, registry persistence, and suspicious outbound connections.
- Monitor credentials and sessions. Watch for abnormal token and authentication activity, as session-token theft can extend compromise beyond stolen passwords.
- Isolate suspected infections quickly. Preserve telemetry, reset exposed credentials, revoke sessions, and investigate accounts accessible from the device.
- Test incident response plans. Exercises should validate endpoint containment, credential revocation, environment-wide hunting, and recovery procedures.
The 6,300 WebAdvisor blocks represent attempts to reach malicious sites, not confirmed infections. WeedHack’s distribution model shows why disrupting C2 infrastructure alone does not eliminate SEO poisoning, software impersonation, or trusted-service abuse.
Read more: Browser fingerprinting can also hide malicious download infrastructure from scanners, as seen in a recent ClickFix campaign spanning more than 250 domains.
.





