Skip to content

WeedHack

WeedHack is a Minecraft-focused malware-as-a-service platform active since at least January 2026.

Profile source: Mallory opens in a new tab

WeedHack

Family profile

WeedHack is a Minecraft-focused malware-as-a-service platform active since at least January 2026. It primarily deploys an infostealer through trojanized Java archives presented as Minecraft mods, clients, cheats, and utilities. The operation targets Minecraft players worldwide and has been associated with large-scale victimization. Its operators and customers have not been publicly attributed to a named threat group.

WeedHack distribution relies on search-engine optimization poisoning, cloned websites impersonating legitimate Minecraft projects, deceptive free-download offers, and malicious links promoted through YouTube, Discord, file-hosting services, code-hosting repositories, and Minecraft community platforms. The spoofed sites commonly reproduce legitimate branding, installation documentation, developer credits, and links to genuine project resources to increase credibility.

The malware uses a multistage infection chain. It can collect host information, steal Minecraft session data, browser passwords and cookies, credentials for gaming and messaging applications, and cryptocurrency-wallet data. Stolen session tokens can enable account takeover. WeedHack uses blockchain-based command-and-control discovery through EtherHiding and validates retrieved infrastructure data cryptographically. It also employs in-memory second-stage delivery, Windows Defender exclusions, privilege escalation, scheduled-task persistence, and obfuscation to hinder detection.

The free service tier concentrates on information and session theft. Low-cost premium access adds remote desktop and screen control, webcam access, keylogging, reverse-shell functionality, and remote file-management capabilities through a web dashboard. These features support credential theft, surveillance, account hijacking, and harassment of compromised users.

Capabilities

  • Credential Theft
  • Crypto Theft
  • Defense Evasion
  • Exfiltration
  • Keylogging
  • Persistence
  • Post Exploitation
  • Privilege Escalation
  • Reconnaissance
  • Session Hijacking

Observed infrastructure

Last seven days

First activity
Sep 16, 2026
Last activity
Sep 16, 2026
Feed role
Distribution
Host form
0 IP / 1 hostnames

Leading locations

  • SE1

Leading providers

  • Cloudflare, Inc.1

Infrastructure traits

  • Anycast 1
  • Hosting 1

Samples

Recent associated samples

MITRE ATT&CK

WeedHack in ATT&CK

36 distinct techniques

Reporting

Research mentioning WeedHack

Aug 25
Security Affairs

Fake Minecraft Sites Are Still Spreading WeedHack After C2 Takedown

Malicious websites impersonating Minecraft clients, mods, and related tools are continuing to distribute the WeedHack malware family despite prior command-and-control disruption. McAfee Labs identified at least 10 active sites and multiple file-hosting accounts tied to the campaign, while McAfee WebAdvisor blocked more than 6,300 attempts to reach them in the past month. The lures are amplified through SEO poisoning, YouTube links, Discord, GitHub repositories, and trusted Minecraft community platforms, with attackers using convincing lookalike pages to trick gamers into downloading malicious files. The infection chain delivers Java JAR payloads that collect system information, add Microsoft Defender exclusions, and steal credentials, browser data, cookies, and cryptocurrency wallets from infected hosts. Earlier reporting linked the Malware-as-a-Service operation to at least 116,464 infected systems and 2,000 to 3,000 new victims per day, while researchers said the operators used EtherHiding to retrieve active server addresses from the Ethereum blockchain and keep the campaign resilient after takedowns. One spoofed site was reportedly built with the AI website builder Lovable, underscoring how easily attackers can create realistic malware-delivery infrastructure.

Aug 25
Cyber Security News

Top Google Results for Minecraft Client Led Gamers to Malware, McAfee Finds

Aug 24
The Hacker News

Weedhack Malware Spreads via Fake Minecraft Clients and SEO Poisoning

May 13
Securelist

Evolution of JSWorm ransomware | Securelist

Nefilim emerged as a distinct ransomware operation built from Nemty 2.5 code, abandoning the earlier ransomware-as-a-service model in favor of private, targeted intrusions and email-based ransom negotiations. The malware encrypts files with AES-128 and protects keys with RSA-2048, appends the .NEFILIM extension, and drops NEFILIM-DECRYPT.txt, while also stealing data and threatening to publish it if victims do not pay. Researchers linked Nefilim to the broader JSWorm/Nemty/Nefilim lineage through shared cryptographic logic, ransom-note patterns, and infrastructure, showing a progression from mass distribution via the RIG exploit kit, spam, and the Trik/Phorpiex botnet to enterprise-focused attacks.

May 12
Qualys

Nefilim Ransomware: Tactics, Impact, and Mitigation Strategies | Qualys

Feb 23
Trend Micro Research

An Analysis of the Nefilim Ransomware | Trend Micro (US)

Dec 28
Bleeping Computer

Home appliance giant Whirlpool hit in Nefilim ransomware attack

Apr 2
Mcafee Labs

Nemty Ransomware - Learning by Doing | McAfee Blog

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.