Press play to start listening
Gamers searching for Minecraft game clients, mods, and cheats are being directed to fake websites that install WeedHack, a Windows malware service capable of stealing accounts, passwords, files, and cryptocurrency wallet data.
The malware is sold to cybercriminals through free and paid plans. Its more expensive version adds keylogging, webcam access, remote screen control, and command-line access to an infected computer.
McAfee first documented the operation in June 2026 targeting Minecraft users. Although WeedHack’s original command server and customer dashboard later went offline, a new investigation found that other websites and download links continued spreading the malware. McAfee WebAdvisor blocked more than 6,300 attempted visits to associated sites during the past month.
In one test, McAfee found that the first two Google results for Xenon Client led to websites distributing WeedHack. The operators used SEO poisoning to push malicious pages higher in search results and place them in front of people looking for legitimate Minecraft software.
Minecraft has long been a popular lure for malware campaigns. In 2021 alone, more than 300,000 malware cases were associated with the game, the highest reported figure for any gaming title that year.
WeedHack Continues After Its Original Server Went Offline
McAfee first documented WeedHack in June as a malware-as-a-service operation that had been active since January 2026. Its investigation identified more than 3,820 malicious JAR files and over 240 distribution URLs.
The campaign dashboard recorded 116,464 hits, with roughly 2,000 to 3,000 added daily. That figure came from the criminals’ own system and should not be described as 116,464 confirmed infections or unique victims.
Following McAfee’s first disclosure, WeedHack’s original command server and customer dashboard went offline. The disruption did not remove the malicious files or websites already promoting them. McAfee’s latest report found several pages and file-hosting links that remained active and continued serving the malware.
Some fake sites copied feature lists, installation instructions, FAQs, developer names, and screenshots from genuine projects. Several also linked to authentic GitHub repositories or Discord communities so that visitors would see familiar references before clicking the malicious download.
The campaign makes heavy use of services gamers already know. McAfee found that 49.6% of the malicious URLs were Discord links, 23.4% used MediaFire, 8.2% used GitHub, and 4.6% used Dropbox. One fraudulent site was built with an AI website generator, reducing the work needed to publish a convincing imitation.
What WeedHack Can Steal
A Minecraft mod is commonly delivered as a Java archive, or JAR file. Running a malicious JAR can launch the promised game modification while also installing malware, so a client that appears to work is not proof that the download is safe.
WeedHack’s free service could steal Minecraft session IDs, which are tokens showing that a player has already logged in. An attacker who obtains a valid session may be able to hijack the account without learning its password.
The same malware collected saved passwords and cookies from 36 browsers, credentials for Discord, Steam and Telegram, and data from 56 browser-based cryptocurrency wallets and 12 desktop wallets. It could also search for files using 24 keywords, take screenshots and collect the computer’s IP address, hardware details and account name.
The premium tier, priced from $5 per month, added webcam access, live screen viewing, keyboard and mouse control, keylogging, command-line access and remote file management. The earlier WeedHack service also offered lifetime access for $24.99 and tutorials explaining how customers could spread customized malware through search results and YouTube videos.
How Minecraft Players Can Avoid Fake Downloads
Gamers should obtain clients and mods from the developer’s official page or a reputable mod platform, then confirm that the web address is correct. Search position, polished branding and a link to a genuine repository do not prove that the download itself is trustworthy.
Oliver Devane, senior security researcher and principal engineer at McAfee, advised users to scan files before opening them and question offers involving free paid clients, premium functions or exclusive cheats.
Players should never disable antivirus protection because a download page requests it. Security warnings should be investigated before any flagged file is allowed to run, while current versions of Windows, Java, browsers and security software can block known infection methods.
Anyone who has run a suspected WeedHack file should disconnect the computer from the network, scan it, revoke Minecraft and other active sessions, change passwords from a clean device, and review cryptocurrency wallets for unauthorized activity.

