All About Cookies is an independent, advertising-supported website. Some of the offers that appear on this site are from third-party advertisers from which All About Cookies receives compensation. This compensation may impact how and where products appear on this site (including, for example, the order in which they appear).
All About Cookies does not include all financial or credit offers that might be available to consumers nor do we include all companies or all available products. Information is accurate as of the publishing date and has not been provided or endorsed by the advertiser.
The All About Cookies editorial team strives to provide accurate, in-depth information and reviews to help you, our reader, make online privacy decisions with confidence. Here's what you can expect from us:
- All About Cookies makes money when you click the links on our site to some of the products and offers that we mention. These partnerships do not influence our opinions or recommendations. Read more about how we make money.
- Partners are not able to review or request changes to our content except for compliance reasons.
- We aim to make sure everything on our site is up-to-date and accurate as of the publishing date, but we cannot guarantee we haven't missed something. It's your responsibility to double-check all information before making any decision. If you spot something that looks wrong, please let us know.
The next time your child asks you to download a cool new Minecraft mod or client, think twice, as it could open the gates to a cybercriminal sitting on the other side of your screen.
Security researchers have found a new malware campaign called WeedHack, which hides behind these downloads and can quietly steal passwords, browser cookies, crypto wallet data, and even give attackers remote access to your device.[1]
Worse still, the premium version of the malware (which, unfortunately, is very affordable) can give attackers access to your webcam, keyboard, screen, and mouse, all without you knowing.
Here’s everything you need to know about WeedHack and how you can stay safe from Minecraft malware.
How does WeedHack spread
Examples of malicious Minecraft websites
What can you do to protect yourself
Bottom line
What is WeedHack
In early June, a McAfee Labs report found a new malware-as-a-service campaign named WeedHack, active since January 2026. It allowed attackers to remotely access victims’ screens and webcams and track the malware’s performance through a dashboard.
The report found 3,820 unique malicious JAR files and 240 URLs distributing the malware. The campaign uses YouTube and SEO poisoning to generate traffic to these malicious URLs.
At the time of the first report, the campaign had accumulated 116,464 hits, averaging 2,000 to 3,000 hits per day.
Now, a new follow-up report published by McAfee Labs says that since the first report, the C2 server has been taken down and the dashboard has disappeared.
However, the malware is still being actively distributed through URLs. Of these, 49.6% were Discord links, 23.4% were MediaFire links, while 8.2% and 4.6% were GitHub and Dropbox links, respectively.
The MaaS campaign advertised both a free tier and a premium tier. The free tier itself is pretty threatening, as it could allow attackers to target Minecraft session IDs and four Minecraft launchers, collect system information, steal passwords and cookies from 36 different browsers, and target 56 browser-based crypto wallets along with 12 desktop crypto wallets.
It can also steal Discord, Steam, and Telegram credentials, search for files using 24 different keywords, and capture screenshots.
The premium subscription, meanwhile, takes things to the next level. For just $5 per month, attackers get remote-access capabilities such as webcam access, keylogging, screen sharing with keyboard and mouse access, and file-management functions.
How does WeedHack spread
The first report highlighted YouTube as a key platform for spreading the malware.
Attackers created professionally crafted videos with backgrounds and overlays — without even using artificial intelligence — allowing these high-quality videos to generate consistent traffic.
Most of these videos advertise fake websites, with download links placed in the description and comment sections. That’s a classic phishing tactic.
SEO poisoning has also been identified as a major distribution channel. Threat actors created websites for legitimate Minecraft clients, hosted exclusively on platforms like GitHub, and without an actual website of their own.
SEO poisoning isn’t unique to the WeedHack campaign, either. Recently, Fortra Intelligence and Research Experts (FIRE) published a report highlighting a 40% increase in SEO poisoning.
They found threat actors impersonating banking portals through typosquatted domains and getting them to rank higher in search engine results. Innocent users visiting these results could have their banking passwords stolen, potentially leading to financial fraud.
Examples of malicious Minecraft websites
The McAfee report highlights several websites that impersonate legitimate Minecraft clients and distribute WeedHack. Three particularly notable examples include:
Radium-client.com: This website replicates the legitimate RadiumClient.com and offers its Minecraft client for free, even though the legitimate version costs $9.99 per month. The downloadable JAR file is infected with WeedHack.
Xenon Client: Researchers found that the top two Google results for “Xenon Client” directed users to websites spreading WeedHack. One malicious site also included detailed installation guides, FAQs, credits, and links to the legitimate GitHub repository to appear trustworthy.
Glazed Client: The fake Glazed-client.com website closely replicates the legitimate Glazedclient.com, including its feature list, archive, credits, and FAQ sections. The site was distributing WeedHack while presenting itself as the legitimate project.
What can you do to protect yourself
Since WeedHack uses legitimate-looking websites and YouTube videos to spread the attack, any innocent gamer could end up installing malware on their devices. Still, you can take a few steps to stay safe.
- Use a third-party antivirus program: Top anti-malware software includes online web protection that can flag suspicious websites before you interact with them. This way, even if you land on a typosquatted domain, the antivirus can warn you. Antivirus software also scans downloaded files and compares them against known malware signatures. If the file you downloaded is flagged by your antivirus, do not ignore the warning, assuming it’s a false positive.
- Download only from official sources: Download Minecraft clients or mods only from reputable, well-known mod platforms and websites. Check the URL of the website you landed on, and if something seems off — such as a spelling error or an unwarranted dash — it could be a fake domain.
- Do not fall for free offers: Many impersonation websites offer otherwise paid Minecraft clients for free. If an offer appears too good to be true, it usually is.
- Keep your devices and software updated: Make sure your operating system, browser, games, and security software are up to date. These updates can help protect your devices against known vulnerabilities.
- Use an identity theft protection service: If you’ve already downloaded a Minecraft client, there’s a chance your personal information is with malicious parties, who could use it for phishing scams and account takeovers or sell it to data brokers. Use an identity theft protection service to scan leaked databases and the dark web for your personal information.
Bottom line
The new WeedHack malware has put gamers at serious risk. Downloading the wrong Minecraft client or visiting the wrong website could install malware on your device that could swoop in on your Minecraft session and steal passwords, browser cookies, and other personal information.
Even though the campaign’s C2 server has been taken down, malicious websites are still actively distributing WeedHack. If misused, the stolen information could lead to identity theft, financial fraud, and account takeovers.
That said, strong cyber hygiene, along with third-party protection tools such as antivirus software and an identity theft protection service, can help you avoid this threat.