Fake Minecraft Sites Are Spreading Malware That Can Steal Your Passwords, Cookies, and Crypto. Here’s How To Stay Safe

A new Minecraft malware campaign can steal your passwords, browser cookies, crypto data, and even give attackers access to your webcam and screen.
We receive compensation from the products and services mentioned in this story, but the opinions are the author's own. Compensation may impact where offers appear. We have not included all available products or offers. Learn more about how we make money and our editorial policies.

The next time your child asks you to download a cool new Minecraft mod or client, think twice, as it could open the gates to a cybercriminal sitting on the other side of your screen.

Security researchers have found a new malware campaign called WeedHack, which hides behind these downloads and can quietly steal passwords, browser cookies, crypto wallet data, and even give attackers remote access to your device.[1]

Worse still, the premium version of the malware (which, unfortunately, is very affordable) can give attackers access to your webcam, keyboard, screen, and mouse, all without you knowing.

Here’s everything you need to know about WeedHack and how you can stay safe from Minecraft malware.

In this article
What is WeedHack
How does WeedHack spread
Examples of malicious Minecraft websites
What can you do to protect yourself
Bottom line

What is WeedHack

In early June, a McAfee Labs report found a new malware-as-a-service campaign named WeedHack, active since January 2026. It allowed attackers to remotely access victims’ screens and webcams and track the malware’s performance through a dashboard.

The report found 3,820 unique malicious JAR files and 240 URLs distributing the malware. The campaign uses YouTube and SEO poisoning to generate traffic to these malicious URLs.

At the time of the first report, the campaign had accumulated 116,464 hits, averaging 2,000 to 3,000 hits per day.

Now, a new follow-up report published by McAfee Labs says that since the first report, the C2 server has been taken down and the dashboard has disappeared.

However, the malware is still being actively distributed through URLs. Of these, 49.6% were Discord links, 23.4% were MediaFire links, while 8.2% and 4.6% were GitHub and Dropbox links, respectively.

The MaaS campaign advertised both a free tier and a premium tier. The free tier itself is pretty threatening, as it could allow attackers to target Minecraft session IDs and four Minecraft launchers, collect system information, steal passwords and cookies from 36 different browsers, and target 56 browser-based crypto wallets along with 12 desktop crypto wallets.

It can also steal Discord, Steam, and Telegram credentials, search for files using 24 different keywords, and capture screenshots.

The premium subscription, meanwhile, takes things to the next level. For just $5 per month, attackers get remote-access capabilities such as webcam access, keylogging, screen sharing with keyboard and mouse access, and file-management functions.

How does WeedHack spread

The first report highlighted YouTube as a key platform for spreading the malware.

Attackers created professionally crafted videos with backgrounds and overlays — without even using artificial intelligence — allowing these high-quality videos to generate consistent traffic.

Most of these videos advertise fake websites, with download links placed in the description and comment sections. That’s a classic phishing tactic.

SEO poisoning has also been identified as a major distribution channel. Threat actors created websites for legitimate Minecraft clients, hosted exclusively on platforms like GitHub, and without an actual website of their own.

SEO poisoning isn’t unique to the WeedHack campaign, either. Recently, Fortra Intelligence and Research Experts (FIRE) published a report highlighting a 40% increase in SEO poisoning.

They found threat actors impersonating banking portals through typosquatted domains and getting them to rank higher in search engine results. Innocent users visiting these results could have their banking passwords stolen, potentially leading to financial fraud.

Examples of malicious Minecraft websites

The McAfee report highlights several websites that impersonate legitimate Minecraft clients and distribute WeedHack. Three particularly notable examples include:

Radium-client.com: This website replicates the legitimate RadiumClient.com and offers its Minecraft client for free, even though the legitimate version costs $9.99 per month. The downloadable JAR file is infected with WeedHack.

Radium-client.com fake website

Xenon Client: Researchers found that the top two Google results for “Xenon Client” directed users to websites spreading WeedHack. One malicious site also included detailed installation guides, FAQs, credits, and links to the legitimate GitHub repository to appear trustworthy.

Xenon Client Google search

Glazed Client: The fake Glazed-client.com website closely replicates the legitimate Glazedclient.com, including its feature list, archive, credits, and FAQ sections. The site was distributing WeedHack while presenting itself as the legitimate project.

What can you do to protect yourself

Since WeedHack uses legitimate-looking websites and YouTube videos to spread the attack, any innocent gamer could end up installing malware on their devices. Still, you can take a few steps to stay safe.

  1. Use a third-party antivirus program: Top anti-malware software includes online web protection that can flag suspicious websites before you interact with them. This way, even if you land on a typosquatted domain, the antivirus can warn you. Antivirus software also scans downloaded files and compares them against known malware signatures. If the file you downloaded is flagged by your antivirus, do not ignore the warning, assuming it’s a false positive.
  2. Download only from official sources: Download Minecraft clients or mods only from reputable, well-known mod platforms and websites. Check the URL of the website you landed on, and if something seems off — such as a spelling error or an unwarranted dash — it could be a fake domain.
  3. Do not fall for free offers: Many impersonation websites offer otherwise paid Minecraft clients for free. If an offer appears too good to be true, it usually is.
  4. Keep your devices and software updated: Make sure your operating system, browser, games, and security software are up to date. These updates can help protect your devices against known vulnerabilities.
  5. Use an identity theft protection service: If you’ve already downloaded a Minecraft client, there’s a chance your personal information is with malicious parties, who could use it for phishing scams and account takeovers or sell it to data brokers. Use an identity theft protection service to scan leaked databases and the dark web for your personal information.

Bottom line

The new WeedHack malware has put gamers at serious risk. Downloading the wrong Minecraft client or visiting the wrong website could install malware on your device that could swoop in on your Minecraft session and steal passwords, browser cookies, and other personal information.

Even though the campaign’s C2 server has been taken down, malicious websites are still actively distributing WeedHack. If misused, the stolen information could lead to identity theft, financial fraud, and account takeovers.

That said, strong cyber hygiene, along with third-party protection tools such as antivirus software and an identity theft protection service, can help you avoid this threat.

Combine Sophisticated Malware Protection With $1M in ID Theft Insurance
4.5
Editorial Rating
Get Deal
On Aura Antivirus's website
2026 Editors’ Choice
Best Antivirus With ID Theft Protection
Antivirus Software
Aura Antivirus
PROMOTION: Up to 53% Off
  • Antivirus that passes our malware and drive-by download tests, with fast scans and minimal impact on system performance
  • Bundles with a VPN, password manager, and ad blocker included on every plan, no add-ons required
  • Available with Aura identity theft protection plans if you want device security and ID monitoring in one subscription
Author Details
Krishi Chowdhary specializes in digital privacy, cybersecurity, and consumer technology. He has written extensively on online privacy tools and broader cybersecurity topics, including online scams, data breaches, age verification, and emerging digital threats. Krishi believes technology reporting should empower readers, not confuse them, and is committed to making even the most technical subjects easy to understand without compromising on accuracy or depth. His work has appeared in leading technology publications, including CNET, ExpressVPN, and TechRadar, where he has covered topics ranging from cybersecurity incidents and privacy product announcements to artificial intelligence and major technology news

Citations

[1] WeedHack Returns: How SEO Poisoning is Leading Minecraft Fans to Malware