Active Exploitation AlertAug 25, 20266 min read← All posts
Weedhack Malware Actively Exploiting Minecraft Modding Community
Executive Summary
The Weedhack malware campaign represents a significant escalation in the abuse of the Minecraft gaming ecosystem, leveraging advanced Malware-as-a-Service (MaaS) techniques and SEO poisoning to propagate infostealer and remote access trojan (RAT) payloads. Since early 2026, threat actors have distributed Weedhack via counterfeit Minecraft client and mod websites, as well as through poisoned search engine results, Discord, YouTube, and Reddit. The malware’s technical sophistication is underscored by its use of blockchain-based command-and-control (C2) infrastructure, multi-stage Java payloads, and modular capabilities for credential theft, session hijacking, and persistent remote access. Over 116,000 infections have been observed globally, with a victimology profile spanning the United States, Germany, India, the United Kingdom, and several other countries. The campaign’s impact extends beyond credential and cryptocurrency theft, enabling harassment and cyberbullying within gaming communities. This report provides a comprehensive technical analysis of the Weedhack malware, its tactics, techniques, and procedures (TTPs), exploitation in the wild, and actionable mitigation strategies.
Threat Actor Profile
The operators behind Weedhack are not attributed to any known advanced persistent threat (APT) group but instead run a commercial MaaS operation. The service is marketed primarily to teenagers and young adults within the Minecraft modding and cheating communities. The threat actor ecosystem is decentralized, with multiple customers purchasing access to the malware’s infrastructure and capabilities. The campaign’s monetization model includes credential theft, cryptocurrency wallet exfiltration, and the sale of access to compromised accounts. The use of blockchain-based C2 (via Ethereum smart contracts and the EtherHiding technique) demonstrates a high degree of operational security and resilience, complicating takedown efforts and attribution.
Technical Analysis of Malware/TTPs
Weedhack is delivered as a trojanized Java Archive (JAR) file masquerading as a legitimate Minecraft client or mod. Upon execution, the malware relaunches itselfon. The initial payload decrypts campaign-specific configuration data, including Ethereum JSON-RPC endpoints, smart contract addresses, and embedded RSA public keys for C2 validation
The infection chain proceeds through several stages. The second-stage payload employs Java Native Interface Compilation (JNIC) obfuscation, converting Java bytecode to native code to hinder static analysis. This stage performs extensive system reconnaissance, disables or excludes itself from Windows Defender, captures screenshots, and harvests credentials from browsers, Discord, Steam, and Telegram. It also collects hardware and operating system information.
Persistence is established via registry run keys and scheduled tasks, ensuring the malware executes upon system startup. Advanced modules provide premium RAT features, including remote desktop access, webcam activation, keylogging, reverse shell capabilities, file management, and screen sharing. Data exfiltration is conducted over attacker-controlled infrastructure, with C2 endpoints dynamically retrieved from the Ethereum blockchain and validated using RSA signatures (the EtherHiding technique).
The distribution infrastructure is extensive. Fake domains such as glazed-client[.]com, radium-client[.]com, seedcrackerx.github[.]io, cheatlib[.]xyz, meteorclients[.]com, 22qq-client[.]com, kryptonclientcrack.lovable[.]app, nova-client[.]com, xenoclient[.]lol, and xenonclient[.]com are used to impersonate legitimate Minecraft modding sites. Malicious payloads are hosted on Discord (accounting for nearly half of all observed malicious URLs), MediaFire, GitHub, and other file-sharing platforms. SEO poisoning ensures that these fake sites often outrank legitimate sources on major search engines, including Google, Bing, Brave, and DuckDuckGo.
The malware’s TTPs align with several MITRE ATT&CK techniques: T1189 (Drive-by Compromise), T1566.002 (Spearphishing via Service), T1059.005 (Command and Scripting Interpreter: JavaScript/JScript), T1547.001 (Registry Run Keys/Startup Folder), T1053.005 (Scheduled Task/Job: Scheduled Task), T1555 (Credentials from Password Stores), T1556 (Modify Authentication Process), T1113 (Screen Capture), T1123 (Audio Capture), T1056.001 (Keylogging), T1041 (Exfiltration Over C2 Channel), and T1071.001 (Web Protocols).
Exploitation in the Wild
The Weedhack campaign has resulted in over 116,000 confirmed infections, with the majority of victims located in the United States, Germany, India, the United Kingdom, Italy, Vietnam, Canada, Norway, Sweden, Finland, and Spain. The malware is primarily distributed through SEO-poisoned search results, leading users to download trojanized Minecraft clients and mods from counterfeit websites. Additional distribution vectors include Discord channels, YouTube video descriptions, and Reddit threads within Minecraft and modding communities.
Victims are typically Minecraft players seeking enhanced clients or mods, including but not limited to Meteor, Radium, Wurst, Aristois, LiquidBounce, Impact, Future, Inertia, Cornos, WWE, 3arthh4ck, Salhack, Phobos, and Gamesense. The malware is not tied to specific versions of these clients but rather to any version obtained from malicious sources.
The impact of exploitation includes credential theft (browser, Discord, Steam, Telegram), cryptocurrency wallet theft, Minecraft session hijacking, webcam and microphone access, keylogging, and persistent remote access. In addition to financial and privacy losses, the malware has been used for harassment, surveillance, and cyberbullying within gaming communities, amplifying its social impact.
Victimology and Targeting
The primary targets of the Weedhack campaign are Minecraft players, particularly those seeking mods or cheat clients from unofficial sources. The victim profile skews toward teenagers and young adults, reflecting the demographics of the Minecraft modding community. Geographically, the campaign has a global reach, with the highest infection rates observed in the United States, Germany, India, the United Kingdom, Italy, Vietnam, Canada, Norway, Sweden, Finland, and Spain.
The malware’s modular design allows threat actors to tailor attacks based on the victim’s profile, enabling targeted credential theft, account hijacking, and persistent surveillance. The use of social engineering, SEO poisoning, and impersonation of popular modding sites increases the likelihood of successful infections among less security-aware users.
Mitigation and Countermeasures
Organizations and individuals can reduce their exposure to Weedhack by implementing a multi-layered defense strategy. Network administrators should block and monitor access to known malicious domains and file hashes associated with the campaign. Security teams should monitor for suspicious Java Archive (JAR) executions, particularly those relaunchingnder exclusions and registry modifications indicative of persistence mechanisms
Outbound connections to Ethereum JSON-RPC endpoints and anomalous blockchain queries should be closely monitored, as these may indicate attempts to retrieve dynamic C2 addresses. Behavioral and sandbox analysis should be employed for all Java-based mods and clients prior to deployment, especially those sourced from unofficial or community-driven platforms.
User education is critical, particularly within gaming communities. Users should be warned of the risks associated with downloading mods or clients from unofficial sources and encouraged to verify the authenticity of websites before downloading any software. Security awareness campaigns should highlight the prevalence of SEO poisoning and the importance of sourcing software only from trusted, official channels.
Endpoint protection solutions should be configured to detect and block the execution of known malicious JAR files and to alert on suspicious process behaviors associated with Weedhack. Regular system audits and threat hunting activities should be conducted to identify and remediate infections promptly.
References
- The Hacker News: Weedhack Malware Spreads via Fake Minecraft Clients and SEO Poisoning
- PolySwarm: From Minecraft Mods to Malware-as-a-Service: Inside the Weedhack Ecosystem
- McAfee Labs: Weedhack Malware Spreads via Fake Minecraft Clients and SEO Poisoning
- Reddit: Weedhack Malware Spreads via Fake Minecraft Clients and SEO Poisoning
- MITRE ATT&CK Framework
About Rescana
Rescana is a leader in third-party risk management (TPRM), providing organizations with a comprehensive platform to assess, monitor, and mitigate cyber risks across their digital supply chain. Our advanced threat intelligence and automation capabilities empower security teams to proactively identify and respond to emerging threats, ensuring robust protection for critical assets and business operations. For more information or to discuss how Rescana can support your cybersecurity strategy, please contact us at info@rescana.com.
Aug 26, 2026
Critical Unpatched Vulnerabilities in Kaltura mwEmbed Expose Organizations to Remote Code Execution and File Read Attacks (CVE-2026-19912, CVE-2026-19913)
Aug 25, 2026
Active Exploitation Alert: WordlistLoader Bypasses Security Defenses to Deliver Amatera Stealer Malware on Windows Systems
Aug 20, 2026
CDN Tsunami: Critical HTTP/3 to HTTP/1.1 Protocol Translation Vulnerability Triggers Up to 350x DoS Amplification Across Major CDN Providers
