Weedhack Malware Spreads via Counterfeit Minecraft Clients and SEO Poisoning

0
18

Key Takeaways

  • Cybercriminals are distributing the Weedhack malware family through spoofed Minecraft‑client websites that mimic legitimate projects.
  • One malicious site was built with the AI‑powered website builder Lovable, showing how low‑cost tools aid convincing fraud.
  • Weedhack follows a multi‑stage infection chain: it gathers system data, creates Microsoft Defender exclusions, and exfiltrates sensitive information via JAR payloads.
  • Nearly half of the malicious URLs point to Discord links; MediaFire and GitHub host the remainder, illustrating abuse of trusted platforms.
  • Fake domains such as glazed-client[.]com, radium-client[.]com, and kryptonclientcrack.lovable[.]app appear at the top of search results via SEO poisoning, outranking official sources.
  • The malware also spreads through legitimate file‑hosting services and community hubs like Planet Minecart and EndMods, with links shared on Discord, Reddit, and similar channels.
  • Defending against the threat requires keeping software updated, downloading only from trusted repositories, scanning files before execution, and refusing any request to disable security protections.
  • This campaign mirrors a June 2026 Check Point operation that used SEO poisoning to push other stealers, underscoring a persistent trend of abusing search‑ranking tactics for malware distribution.

Introduction to the Weedhack Threat
In August 2026, McAfee Labs revealed that several fraudulent websites are actively spreading a malware family dubbed Weedhack to gamers by posing as legitimate Minecraft clients. The attackers have crafted look‑alike sites that replicate the branding, feature lists, FAQs, installation guides, developer credits, and even links to genuine GitHub repositories of popular Minecraft tools. By masquerading as trusted utilities, they lure unsuspecting users into downloading malicious JAR files that ultimately compromise the host system.


AI‑Powered Site Building Lowers the Barrier
A notable aspect of this campaign is the use of Lovable, an artificial‑intelligence‑driven website builder, to construct one of the fraudulent domains. Lovable enables rapid site creation with minimal technical expertise, allowing threat actors to produce convincing replicas of legitimate projects quickly and cheaply. This demonstrates how readily available AI‑assisted tools can lower the entry barrier for cybercriminals seeking to deploy sophisticated social‑engineering attacks.


Technical Breakdown of the Weedhack Infection Chain
Once a victim executes the downloaded JAR file, Weedhack initiates a multi‑stage attack. First, it collects basic system information such as OS version, hardware specifications, and installed software. Next, it modifies Microsoft Defender settings to create exclusions for its own processes, thereby evading detection. Finally, the malware exfiltrates sensitive data—including credentials, cryptocurrency wallets, and personal files—to attacker‑controlled servers. The modular nature of the payload allows additional capabilities to be added in later stages, making it a versatile threat.


Distribution Channels Highlighted by McAfee Labs
McAfee Labs reported that it blocked over 6,300 attempts to access the malicious domains. Analysis of the blocked URLs showed that 49.6 % pointed to Discord links, 23.4 % to MediaFire file‑hosting services, and 8.2 % to GitHub repositories. The remaining URLs were spread across various other platforms. This distribution pattern underscores the attackers’ strategy of leveraging familiar, trusted services to increase the likelihood that users will click and download the payload without suspicion.


Catalog of Spoofed Domains
The researchers enumerated several fake domains that mirror legitimate Minecraft‑related projects:

  • glazed-client[.]com – imitates the open‑source glazedclient[.]com add‑on.
  • radium-client[.]com – copies the paid radiumclient[.]com client.
  • seedcrackerx.github[.]io – mimics seedcrackerx[.]com, a seed‑cracking utility.
  • cheatlib[.]xyz – advertises itself as a “modern Minecraft mod library” with over 1.6 million downloads.
  • meteorclients[.]com – replicates meteorclient[.]com.
  • 22qq-client[.]com – impersonates a Crystal PvP‑server mod.
  • kryptonclientcrack.lovable[.]app – uses Lovable to spoof the paid kryptonclient[.]org tool for DonutSMP.
  • nova-client[.]com – mimics an open‑source Minecraft client.
  • xenoclient[.]lol and xenonclient[.]com – both imitate the Xenon client.

These sites are carefully designed to appear authentic, complete with version numbers, download buttons, and support forums.


SEO Poisoning Elevates Malicious Sites in Search Results
Both the Xenon Client and Nova Client spoofed pages consistently appear at the top of search engine results on Google, Microsoft Bing, Brave Search, and DuckDuckGo. The attackers achieved this positioning through SEO poisoning techniques—optimizing page content, meta tags, and backlinks to outrank the legitimate sources hosted on GitHub and Modrinth. As a result, users searching for “Minecraft client download” or similar queries are presented with the malicious sites first, increasing the chance of accidental infection.


Abuse of Legitimate File‑Hosting and Community Platforms
Beyond bogus websites, Weedhack is disseminated via trusted file‑hosting services and community hubs. Attackers have uploaded the malicious JAR files to platforms such as Planet Minecart and EndMods, which are widely used by Minecraft players seeking mods and enhancements. Links to these files are then shared in Discord servers, Reddit threads, and other gaming forums, exploiting the trust users place in these communities. This multi‑vector approach ensures a broad reach while maintaining a veneer of legitimacy.


Recommended Defensive Measures
To mitigate the risk posed by Weedhack and similar campaigns, users and administrators should:

  1. Keep operating systems, browsers, and security software up to date.
  2. Download Minecraft clients, mods, and tools exclusively from official repositories (e.g., GitHub, Modrinth) or verified developer sites.
  3. Scan all downloaded files with reputable antivirus or sandbox solutions before execution.
  4. Be wary of any prompt that asks to disable antivirus, firewall, or other security protections as a prerequisite for installation.
  5. Verify URLs carefully—look for subtle misspellings or unfamiliar sub‑domains—and avoid clicking links from unsolicited messages.
  6. Employ web‑filtering solutions that block known malicious domains and flag SEO‑poisoned pages.

Adhering to these practices reduces the likelihood of inadvertently installing malware disguised as legitimate gaming software.


Context Within the Wider Threat Landscape
The Weedhack campaign is not isolated. In June 2026, Check Point reported a large‑scale SEO‑poisoning operation that impersonated open‑source and freeware projects to funnel victims through a Traffic Distribution System (TDS) and deliver stealers such as Remus Stealer, AnimateClipper, and the SessionGate framework. Both incidents illustrate a recurring tactic: cybercriminals exploit search‑engine optimization to elevate malicious sites above genuine ones, then leverage trusted distribution channels (Discord, file hosts, community sites) to spread malware. This persistence highlights the need for continual vigilance, improved search‑ranking defenses, and user education about the dangers of downloading software from unverified sources.


SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here