Illustrative image generated with AI
WeedHack survives the takedown: fake Minecraft sites still spreading infostealer
WeedHack malware spreads via fake Minecraft sites post-takedown. Learn about tactics, risks, and protection tips from McAfee.
Text generated by artificial intelligence, published without human review. AI transparency
The WeedHack malware-as-a-service campaign did not stop with the takedown of its command-and-control server. As of late August 2026, ten malicious sites and several file-hosting accounts remain active and continue to distribute the infostealer disguised as Minecraft clients and mods. McAfee Labs reports this in a follow-up report published on August 25, nearly two months after the initial intervention that shut down the attackers' dashboard.
A low-cost criminal service
WeedHack was first observed in early June 2026 by McAfee researcher Aayush Tyagi, but the operation had been active since January. In six months it infected 116,464 systems, at a pace of 2,000-3,000 new victims per day. The service operated on a two-tier model: a free tier accessible with a Discord account, and a premium tier at $5 per month that added webcam surveillance. Operators had a dashboard to view stolen credentials, configure custom payloads, and monitor victims in real time.
After the original report was published in the first week of July 2026, the C2 server was taken down. The dashboard is no longer reachable, but the distribution sites have remained operational. Over the past thirty days, McAfee WebAdvisor blocked more than 6,300 attempts to access these domains.
The deception leverages search engines and communities
WeedHack's spread exploits a structural weakness in Minecraft modding: many popular tools have no official website, only GitHub pages and Discord servers. Attackers create detailed and convincing fake sites, copying features, FAQs, installation instructions, developer information, and even links to legitimate GitHub repositories.
Search engine positioning plays a key role. For the query "Xenon Client," the first two Google results led to fake sites distributing WeedHack, complete with installation guides, free and paid downloads, and links to the real repository. Nova-client.com is a prime example: the client has no official site, and the fake domain ranked above the authentic GitHub repository. 22qq-client.com does the same for a Crystal PVP mod.
The campaign also abused trusted communities such as Planet Minecraft and EndMods, making the scams harder to recognize. A Discord channel promoting fake DonutSMP clients surpassed 1,900 members, while another site offered eight different mods that all distributed the same malware.
Distribution channels and user trust
Most malicious links came from Discord, which alone generated 49.6% of downloads. MediaFire followed with 23.4%, GitHub with 8.2%, and Dropbox with 4.6%. These numbers indicate that attackers focus on channels where players routinely exchange mods and clients, exploiting trust in file-hosting platforms and community servers.
Using legitimate services to host payloads makes infrastructure-level blocking more difficult. In addition, one campaign site was built with lovable.app, an AI-powered web development platform that accepts natural language instructions. This reduces the costs and technical skills needed to launch a new fake gaming site to near zero, accelerating the lifecycle of distribution pages.
How the malware maintains contact: EtherHiding
WeedHack steals session cookies, passwords, browser data, and cryptocurrency wallet contents. To maintain contact with the infrastructure even when individual servers were taken down, developers adopted EtherHiding, a technique that retrieves the active server address from the Ethereum blockchain. In practice, the payload queries the blockchain to obtain the new C2 address, making the simple removal of a specific domain or IP ineffective.
This resilience explains why taking down the main server did not stop distribution. The fake sites continue to operate and serve the malware, which in turn seeks the new point of contact on the blockchain. It is not known whether the original operators are still in charge or whether the infrastructure has passed to others, but the campaign remains active.
Signs to recognize fake sites
Researchers have identified some useful indicators for unmasking impersonation pages. On nova-client.com, the credits section lists generic team names instead of the real developers, a detail that often escapes a superficial read. In general, fake sites tend to be more polished than one would expect from an open source project without an official site: they include FAQs, installation guides, and paid downloads, elements that authentic GitHub repositories do not offer.
The presence of a "download" button on a site that is not the developer's official repository should raise suspicion. The same applies to links shared on Discord or MediaFire that promise "premium" or "cracked" versions of free clients. If a tool asks you to disable your antivirus, treat it as malware, with no exceptions.
McAfee's recommendations
McAfee recommends downloading mods and clients only from official developer repositories or trusted platforms such as Modrinth and CurseForge. These platforms check uploaded files and offer a level of assurance that links shared on Discord or MediaFire cannot provide. For projects that exist only on GitHub, the advice is to use exclusively the authentic repository page, verifying the URL and the presence of signed releases.
There is no specific patch for WeedHack: it is malware, not a vulnerability in a software product. The versions of the affected clients have not been disclosed, because the campaign impersonates multiple tools. Anyone who downloaded clients or mods from suspicious sites in recent months should immediately change passwords for their most important services, enable two-factor authentication, and check cryptocurrency wallets for unauthorized transactions. The presence of anomalous processes or requests for webcam access without reason may indicate an ongoing infection.
The WeedHack case shows that an isolated takedown of the C2 server is not enough to stop a campaign distributed across dozens of channels and supported by blockchain-based resilience techniques. The July shutdown eliminated the attackers' dashboard, but distribution continues. McAfee WebAdvisor monitoring and reporting fake sites remain the most effective tools for limiting the spread at this time.
Sources
This article is an original reworking based on the sources below.
