Weedhack Malware Targets Gamers via Fake Minecraft Clients & SEO Poisoning

Cybersecurity teams have uncovered a malware campaign called Weedhack that’s striking Minecraft players by pretending to be legitimate Minecraft clients. This threat relies on fake websites, popular mod libraries, and search engine manipulation to trick users into downloading harmful software. McAfee Labs reports blocking over 6,300 attempts to reach malicious domains tied to Weedhack.([thehackernews.com](https://thehackernews.com/2026/08/weedhack-malware-spreads-via-fake.html))

How the Deception Works

Attackers have been creating lookalike websites modeled after real Minecraft clients. These sites mimic official branding, features, installation guides, FAQ pages—even claiming GitHub links—to win trust. Some are built using AI tools like Lovable to rapidly spin up convincing impostors.([thehackernews.com](https://thehackernews.com/2026/08/weedhack-malware-spreads-via-fake.html))

The malware first surfaced publicly in June 2026. It spreads using what’s known as SEO poisoning and redirects embedded in YouTube videos, pushing gamers toward malicious downloads. Once the victim downloads the malicious JAR file, Weedhack activates a multi-stage process: collecting system data, manipulating Microsoft Defender settings so certain threats are ignored, and stealing sensitive information from the device.([thehackernews.com](https://thehackernews.com/2026/08/weedhack-malware-spreads-via-fake.html))

Channels & Impersonation Tactics

Nearly half of the Weedhack distribution links are shared through Discord (49.6%), followed by MediaFire (23.4%) and GitHub (8.2%).([thehackernews.com](https://thehackernews.com/2026/08/weedhack-malware-spreads-via-fake.html)) Other infection vectors include hosting services and mod-focused platforms like Planet Minecart and EndMods—sites gamers already trust.([thehackernews.com](https://thehackernews.com/2026/08/weedhack-malware-spreads-via-fake.html)) Many of the malicious domains are almost identical to popular clients—just slight changes in the domain name. For example, glazed-client[.]com mimics glazedclient[.]com; radium-client[.]com mimics radiumclient[.]com; xenonclient[.]com mimics xenonclient[.]lol, among others.([thehackernews.com](https://thehackernews.com/2026/08/weedhack-malware-spreads-via-fake.html))

This deception is enhanced by attackers’ use of SEO tactics that push fake client sites above official sources in search results on Google, Bing, DuckDuckGo, and others, making it more likely players will download Weedhack instead of the real versions.([thehackernews.com](https://thehackernews.com/2026/08/weedhack-malware-spreads-via-fake.html))

Prevention Tips

Avoiding Weedhack requires vigilance. Keep systems updated and stick to trusted platforms like official GitHub repositories or Modrinth for Minecraft clients and mods. Scan any mod tools or files before installing, especially if any of them ask to disable antivirus or security protections. Be wary of clients located via search results that look legitimate but appear unfamiliar.([thehackernews.com](https://thehackernews.com/2026/08/weedhack-malware-spreads-via-fake.html))

This kind of scheme isn’t new. In earlier this year, another campaign pointed out by Check Point used similar impersonation of free tools, redirecting users via traffic-distribution systems to download malware families like Remus Stealer and SessionGate.([thehackernews.com](https://thehackernews.com/2026/08/weedhack-malware-spreads-via-fake.html))

What this means: Weedhack demonstrates how attackers are increasingly targeting gaming communities by cloaking malware in tools players already want. While Minecraft is the setting here, the strategy—fake clients, SEO manipulation, distribution via trusted channels—is widely repeatable. Players should assume risk in every download not explicitly verified and pay attention to details like domain names, hosting platforms, and security prompts. Stakeholders in mod distribution—platform hosts, search engines, gaming influencers—all have roles to play in disrupting this model. Watch next for fraud detection in client sites, better search ranking controls, and stronger checks on community-modified content.