WeedHack Survives the Takedown Through Trusted Links

McAfee says the WeedHack malware-as-a-service campaign is still spreading to Minecraft players after its July takedown, with more than 6,300 blocked access attempts in the past month. The group had already infected 116,464 gamers, and the current wave shows the campaign did not stop when its original command-and-control server went down. The shift is in distribution: McAfee says the operators moved from their own infrastructure to legitimate file-hosting and invite-friendly services, with Discord carrying 49.6% of the observed links, followed by MediaFire, GitHub, and Dropbox. That lets a malware download look like an ordinary shared file or mod link, so removing one bad domain no longer removes the path to the payload. For Minecraft communities, the exposure now lives in the trust users place in shared download links and lookalike client sites, not in a single hosted server. If your players or admins treat Discord, GitHub, or similar links as normal software delivery channels, the campaign can keep reaching them even after the original infrastructure is gone.

Part of the PlainSec briefing for 2026-08-25

Editions

Sources