WeedHack Malware Persists as Fake Minecraft Sites Survive C2 Disruption

Fake Minecraft sites continue distributing WeedHack malware through SEO poisoning and trusted hosting platforms despite disruption of its original C2 infrastructure.

Sep 8, 2026
3 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Disrupting WeedHack’s command-and-control infrastructure did not stop its distribution. Fake Minecraft client sites and trusted hosting services continued serving the malware after the original backend was taken down.

McAfee’s Aug. 20 follow-up found more than 6,300 attempts to reach malicious WeedHack sites during a one-month observation period. ThaiCERT followed with an Aug. 26 warning about the same campaign, which uses SEO poisoning and cloned project pages to steer users toward malicious JAR files.

McAfee’s June 2 investigation first documented WeedHack as a malware-as-a-service (MaaS) operation with more than 3,820 malicious JAR files across 240 distribution URLs. The operation delivers credential-stealing and remote-access malware through fake Minecraft mods, clients, and other downloads.

Fake Minecraft sites continue distributing WeedHack

By the time of McAfee’s Aug. 20 follow-up, WeedHack’s original C2 infrastructure and malware dashboard were no longer active. McAfee said the campaign had been disrupted, but researchers still found active websites serving malicious JAR files. The research does not establish exactly when the C2 infrastructure stopped operating.

ThaiCERT’s Aug. 26 warning separately urged users not to trust search rankings alone when downloading Minecraft add-ons or clients.

SEO poisoning is a central delivery method. The top two Google results McAfee observed for Xenon Client led to sites distributing WeedHack, while other malicious sites copied legitimate projects’ branding, installation instructions, FAQs, developer information, and links to genuine GitHub repositories.

Attackers also relied on legitimate platforms. Among malicious URLs examined, 49.6% were Discord links, 23.4% MediaFire, 8.2% GitHub, and 4.6% Dropbox. Similar trust abuse appeared in an August RMM phishing campaign spanning 46 countries, where attackers used legitimate remote-access software to blend malicious activity into normal IT workflows.

McAfee found WeedHack can steal Minecraft session IDs, browser passwords and cookies, messaging and gaming credentials, cryptocurrency-wallet data, screenshots, and system information. Its premium tier, advertised from $5 per month, adds webcam access, keylogging, reverse-shell execution, screen control, and file-management capabilities.

Advertisement

WeedHack also uses EtherHiding to retrieve its latest C2 domain through an Ethereum smart contract. McAfee observed later stages adding Defender exclusions, scheduled tasks, registry persistence, and remote-access components. Rotating infrastructure has appeared in other infostealer campaigns; Microsoft recently linked more than 30 domains to MacSync Stealer by correlating endpoint and network behavior instead of relying on domains alone.

Layered defenses target WeedHack’s attack chain

Defenses should cover execution control, endpoint behavior, identity exposure, and response readiness rather than rely only on known-domain blocklists.

  • Restrict unapproved JAR execution. Use application control or allowlisting to block unauthorized Java archives in user-writable locations.
  • Limit unnecessary Java and software. Remove unused runtimes and prevent unapproved game clients or mods on managed systems.
  • Strengthen web and download filtering. Apply reputation checks, sandboxing, and file controls to suspicious downloads from legitimate hosting services.
  • Monitor endpoint changes. Hunt for unusual Java activity, Defender exclusions, scheduled tasks, registry persistence, and suspicious outbound connections.
  • Monitor credentials and sessions. Watch for abnormal token and authentication activity, as session-token theft can extend compromise beyond stolen passwords.
  • Isolate suspected infections quickly. Preserve telemetry, reset exposed credentials, revoke sessions, and investigate accounts accessible from the device.
  • Test incident response plans. Exercises should validate endpoint containment, credential revocation, environment-wide hunting, and recovery procedures.

The 6,300 WebAdvisor blocks represent attempts to reach malicious sites, not confirmed infections. WeedHack’s distribution model shows why disrupting C2 infrastructure alone does not eliminate SEO poisoning, software impersonation, or trusted-service abuse.

Read more: Browser fingerprinting can also hide malicious download infrastructure from scanners, as seen in a recent ClickFix campaign spanning more than 250 domains.

.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.