All incidents

WeedHack malware campaign spreads via fake Minecraft clients

malwareopenAug 24, 2026 — Aug 25, 2026
WeedHack malware campaign spreads via fake Minecraft clients

WEEDHACK malware is still infecting users who search for Minecraft clients, with attackers using fake gaming websites to distribute a trojan that harvests passwords and cryptocurrency wallets, according to McAfee Labs. The campaign persisted even after law enforcement seized its command‑and‑control servers, showing the resilience of the operation.

The malicious installers mimic legitimate Minecraft launchers and are hosted on domains that appear high in search results due to SEO poisoning techniques, as outlined by Security Affairs. Once executed, the malware collects stored credentials, browser data and any cryptocurrency keys it can locate, then exfiltrates the information to remote servers controlled by the attackers.

McAfee Labs observed more than 6,300 attempts to access these fraudulent sites within a single month, indicating a steady flow of potential victims. The Hacker News also noted that the majority of the traffic originated from search queries that included terms like "free Minecraft download" or "Minecraft client 2026".

Although the original command‑and‑control infrastructure was disrupted, the attackers have revived the campaign using new web addresses and the same SEO tactics. No specific threat actor has been linked to the activity, but the focus on the gaming community suggests a financially motivated group seeking quick profits.

Users should only download Minecraft or any game client from the official website or authorised app stores, verifying the URL before clicking any download button. Security software should be kept up to date and configured to block known malicious domains, while browser extensions that warn about suspicious sites can provide an extra layer.

Enabling multi‑factor authentication on email, gaming and cryptocurrency accounts limits the usefulness of any stolen credentials. Regularly reviewing account activity and promptly changing passwords after a suspected compromise can help mitigate the impact of the malware.

Intelligence briefing updated Aug 25, 2026

Root sourcewww.mcafee.com
Timeline Coverage

Swipe to explore timeline