Malware · 103 days ago
Minecraft Mods Now Feed a Credential-Theft Service WeedHack has moved past being a bad mod lure. It is now a managed credential-theft and remote-access service, so the risk is not one fake download but a repeatable pipeline that turns gaming trust into stolen logins and live control of infected systems.
McAfee says the campaign has run since January 2026 and uses YouTube, SEO poisoning, and mod/client impersonation to pull victims toward malicious downloads. The operation now has 3,820 unique malicious JARs, more than 240 distribution URLs, and a web dashboard where customers can view stolen credentials, system data, and remote access, with custom payloads for Minecraft 1.21.0 to 1.21.11 .
The service model lowers the barrier for attackers and keeps the problem alive after any single page or video is removed. With active infections rising by about 2,000 to 3,000 per day, this is a broad trust abuse problem for anyone who downloads software from gaming channels, search results, or creator pages.
Timeline Sources 3 sources covering this story
Help Net Security Jun 3
Malware campaign targeting Minecraft users infects over 116,000 systems - Help Net Security
A Malware-as-a-Service operation targeting Minecraft users allows threat actors to remotely access victims' screens, webcams, and files.
The Hacker News Jun 3
Weedhack Attacks Minecraft Users, CountLoader Hits 86K, Miners Spread via Pirated Content
Weedhack malware targets Minecraft players via YouTube and SEO poisoning since Jan 2026, enabling credential theft and remote access.
BleepingComputer Jun 2
Over 116,000 Minecraft systems infected in WeedHack malware campaign
A large-scale malware campaign dubbed WeedHack is targeting Minecraft players and has infected more than 116,000 systems since January.
BleepingComputer Jun 2
Over 116,000 Mincraft systems infected in WeedHack malware campaign
A large-scale malware campaign dubbed WeedHack is targeting Minecraft players and has infected more than 116,000 systems since January.
Entities Part of the PlainSec briefing for 2026-06-04
Editions Related stories
Malware · 103 days ago
Minecraft Mods Now Feed a Credential-Theft Service WeedHack has moved past being a bad mod lure. It is now a managed credential-theft and remote-access service, so the risk is not one fake download but a repeatable pipeline that turns gaming trust into stolen logins and live control of infected systems.
McAfee says the campaign has run since January 2026 and uses YouTube, SEO poisoning, and mod/client impersonation to pull victims toward malicious downloads. The operation now has 3,820 unique malicious JARs, more than 240 distribution URLs, and a web dashboard where customers can view stolen credentials, system data, and remote access, with custom payloads for Minecraft 1.21.0 to 1.21.11 .
The service model lowers the barrier for attackers and keeps the problem alive after any single page or video is removed. With active infections rising by about 2,000 to 3,000 per day, this is a broad trust abuse problem for anyone who downloads software from gaming channels, search results, or creator pages.
Timeline Sources 3 sources covering this story
Help Net Security Jun 3
Malware campaign targeting Minecraft users infects over 116,000 systems - Help Net Security
A Malware-as-a-Service operation targeting Minecraft users allows threat actors to remotely access victims' screens, webcams, and files.
The Hacker News Jun 3
Weedhack Attacks Minecraft Users, CountLoader Hits 86K, Miners Spread via Pirated Content
Weedhack malware targets Minecraft players via YouTube and SEO poisoning since Jan 2026, enabling credential theft and remote access.
BleepingComputer Jun 2
Over 116,000 Minecraft systems infected in WeedHack malware campaign
A large-scale malware campaign dubbed WeedHack is targeting Minecraft players and has infected more than 116,000 systems since January.
BleepingComputer Jun 2
Over 116,000 Mincraft systems infected in WeedHack malware campaign
A large-scale malware campaign dubbed WeedHack is targeting Minecraft players and has infected more than 116,000 systems since January.
Entities Part of the PlainSec briefing for 2026-06-04
Editions Related stories