Malware News Fake Minecraft Clients Spread WeedHack Malware on Windows to Steal Passwords

Brownie2019

Level 23
Thread author
Verified
Well-known
Forum Veteran
Mar 9, 2019
1,078
5,933
2,168
Germany
Gamers searching for Minecraft game clients, mods, and cheats are being directed to fake websites that install WeedHack, a Windows malware service capable of stealing accounts, passwords, files, and cryptocurrency wallet data.

The malware is sold to cybercriminals through free and paid plans. Its more expensive version adds keylogging, webcam access, remote screen control, and command-line access to an infected computer.

McAfee first documented the operation in June 2026 targeting Minecraft users. Although WeedHack’s original command server and customer dashboard later went offline, a new investigation found that other websites and download links continued spreading the malware. McAfee WebAdvisor blocked more than 6,300 attempted visits to associated sites during the past month.

In one test, McAfee found that the first two Google results for Xenon Client led to websites distributing WeedHack. The operators used SEO poisoning to push malicious pages higher in search results and place them in front of people looking for legitimate Minecraft software.

Minecraft has long been a popular lure for malware campaigns. In 2021 alone, more than 300,000 malware cases were associated with the game, the highest reported figure for any gaming title that year.
Read more:
 
Security takeaway

This is a good example of why Minecraft clients, cheats, and mods downloaded from search results should be treated cautiously. SEO rankings do not prove that a website or download is legitimate, and fake “clients” can request permissions or install additional components unrelated to Minecraft.

Recommended precautions:

  • Download Minecraft and mods only from the official publisher or well-established project pages.
  • Avoid cheats, cracked launchers, “free” premium clients, and downloads that require disabling antivirus protection.
  • Check the file’s digital signature and scan it with reputable security software before running it.
  • Submit suspicious files or URLs to VirusTotal, while remembering that a clean result does not guarantee safety.
  • Use unique passwords and enable multifactor authentication, especially for Microsoft, email, and cryptocurrency accounts.
  • If a suspicious program was executed, disconnect the computer from the internet, perform an offline or full security scan, and change passwords from a separate trusted device.

The reported figures and campaign timeline should be checked against McAfee’s original research, but the general warning is sound: unofficial Minecraft software is a common malware distribution lure, and search-engine placement alone should never be treated as a trust signal.