Weedhack Malware Spreads via Fake Minecraft Clients and SEO Poisoning

Weedhack Malware Spreads via Fake Minecraft Clients and SEO Poisoning

Cybersecurity experts have discovered that numerous websites continue to actively distribute a malware family called Weedhack to gamers by pretending to be Minecraft clients.

According to McAfee Labs, over 6,300 attempts to access harmful sites were detected and blocked, with the researchers identifying imitation gaming websites crafted to resemble legitimate projects. These sites include similar branding, feature lists, FAQs, installation instructions, developer acknowledgments, and links to authentic GitHub repositories.

Significantly, one of the identified sites was created using Lovable, an AI-driven website builder, demonstrating how easily accessible tools can reduce barriers and facilitate the creation of convincing malicious sites.

Weedhack was initially reported by the cybersecurity firm in June 2026, outlining its use of SEO poisoning and YouTube to divert traffic to fraudulent domains. The attack initiates a multi-stage process that ends with the deployment of JAR payloads capable of gathering system information, establishing Microsoft Defender exclusions, and stealing sensitive data from the infected host.

“Almost half of the malicious URLs found were Discord links (49.6%), followed by MediaFire (23.4%) and GitHub (8.2%), indicating how attackers can exploit familiar platforms alongside counterfeit websites to spread malware,” stated McAfee Labs researcher Aayush Tyagi.

Below are some of the fraudulent domains distributing the malware:

  • glazed-client[.]com, which imitates glazedclient[.]com, a free and open-source Minecraft add-on of the same name
  • radium-client[.]com, which mimics radiumclient[.]com, a paid Minecraft client
  • seedcrackerx.github[.]io, which replicates seedcrackerx[.]com, a Minecraft seed cracking software
  • cheatlib[.]xyz, which claims to be a “modern Minecraft mod library” with over 1.6 million downloads
  • meteorclients[.]com, which imitates meteorclient[.]com
  • 22qq-client[.]com, which impersonates a Minecraft mod of the same name for Crystal PvP servers
  • kryptonclientcrack.lovable[.]app, which replicates kryptonclient[.]org, a paid Minecraft tool for DonutSMP server
  • nova-client[.]com, which pretends to be an open-source Minecraft client
  • xenoclient[.]lol and xenonclient[.]com, which impersonate Xenon client

It is important to note that both the Xenon Client and Nova Client websites rank highly in search results across various search engines such as Google, Microsoft Bing, Brave Search, and DuckDuckGo, enabling unsuspecting users to download clients infected with Weedhack.

“The legitimate client is hosted on GitHub and Modrinth; however, attackers have created a counterfeit website and utilized SEO poisoning techniques to surpass the official sources in search rankings,” McAfee Labs reported.

In addition to fake domains, file hosting services and GitHub repositories have been noted as spreading Weedhack, with links to these sites shared via Discord, Reddit, and other communication platforms. Another method of propagation involves hosting the JAR files on Planet Minecart and EndMods, both of which are recognized destinations for Minecraft tools and enhancements.

To mitigate the threat, it is recommended to keep devices updated, rely on trusted sources, scan files before opening them, and be cautious when any mod or cheat requests disabling security measures prior to installation.

This is not the first instance of SEO poisoning campaigns targeting popular tools to distribute malware. In June 2026, Check Point highlighted a large-scale operation that impersonated open-source and freeware projects to mislead unsuspecting users through a Traffic Distribution System (TDS) and deliver malware families such as Remus Stealer, AnimateClipper, and the SessionGate framework.

Source: Original article

Leave a Reply

Your email address will not be published. Required fields are marked *

Back To Top