WeedHack Malware Continues to Spread via Fake Minecraft Sites

WeedHack Malware Continues to Spread via Fake Minecraft Sites

First seen 25 Aug 2026, 08:21 UTC ThehackernewsSecurityaffairs.Co 51.9

Article Content

Browse articles
ThreatCluster

Despite the takedown of its command-and-control infrastructure, the WeedHack malware campaign persists with ten active malicious sites still distributing the infostealer. McAfee Labs reported that these sites are disguised as fake Minecraft clients, leveraging SEO poisoning to rank high in search results. Users searching for Minecraft-related downloads are likely to encounter these malicious sites, leading to potential infections. The malware primarily targets Windows systems and is designed to steal sensitive information. The ongoing presence of these sites indicates a significant challenge in mitigating the WeedHack threat. Security professionals are urged to educate users about the risks associated with downloading software from unofficial sources. The situation remains dynamic, with continuous monitoring necessary to combat the spread of this malware.

Key Points: • WeedHack malware is still active despite C2 takedown efforts. • Ten fake Minecraft sites are distributing the malware through SEO poisoning. • Users are at risk of infection when downloading from unofficial sources.

Timeline

2026-08-24
The Hacker News report on WeedHack
The Hacker News reported on the methods used by WeedHack malware to spread, including fake clients and SEO tactics.
Thehackernews
2026-08-25
McAfee Labs report on WeedHack
McAfee Labs published a report detailing the ongoing spread of WeedHack malware via fake Minecraft sites.
Securityaffairs.Co