WeedHack is a Minecraft-focused Malware-as-a-Service operation centered on trojanized mods, clients, cheats, and utilities, primarily targeting Windows gamers. Active since at least January 2026, it has been associated with large-scale compromise of Minecraft players through fake download portals, cloned project websites, poisoned search results, and malicious links promoted in YouTube, Discord, and other gaming communities. The operation commonly impersonates legitimate Minecraft tooling and abuses trusted file-sharing and community platforms to make malicious downloads appear authentic.
WeedHack is best characterized as an infostealer platform with optional remote-access features. Its free tier has been reported to steal Minecraft session data, browser cookies, saved passwords, credentials from applications such as Discord, Steam, and Telegram, cryptocurrency wallet data, screenshots, and general system information. Premium tiers add more intrusive surveillance and control functions, including webcam access, keylogging, screen viewing or remote desktop capability, command execution or reverse shell access, and remote file management. Operators access victim data and payload-building features through a clear-web dashboard.
Technical reporting describes a multi-stage Java-led infection chain in which malicious JAR files act as initial payloads and retrieve later stages. The malware has been observed using EtherHiding-style command-and-control discovery via Ethereum blockchain data, RSA verification of returned infrastructure information, in-memory retrieval of later stages, obfuscation through native components, Windows Defender exclusions, privilege escalation, and persistence through scheduled tasks and related mechanisms. Later-stage components have been associated with both credential theft and remote-access backdoor functionality.
The campaign has been widely linked to SEO poisoning and fake Minecraft client or mod sites that copy branding, installation instructions, FAQs, and links to legitimate developer resources to build trust. Distribution has also been tied to YouTube lures and links shared through Discord and similar communities. Reporting consistently identifies Minecraft players as the primary victim population, with the campaign notable both for its scale and for lowering the barrier to abuse by offering inexpensive or free access to operators.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
Неколку веб-страници сè уште активно дистрибуираат ... Weedhack до гејмери, претставувајќи ја како Minecraft клиенти.
Additionally, the utility establishes an enduring presence by creating a custom background task. This persistent helper forces the computer to restart the malware every time a user logs into the terminal.
For un-paying subscribers, the script simply harvests saved browser cookies and Discord access tokens.
The malware stole session cookies, passwords, browser data, and cryptocurrency wallet contents...
The malware ... used EtherHiding, a technique that fetches the attacker’s active server address from the Ethereum blockchain, to maintain contact with its infrastructure even when individual servers were shut down.
Нападот активира повеќефазен процес кој завршува со распоредување на JAR payload-и
146 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware family distributed via fake Minecraft client websites and SEO poisoning. The infection chain ends with JAR payloads that collect system information, add Microsoft Defender exclusions, and steal sensitive data from compromised devices.
WeedHack is an infostealer offered as a Malware-as-a-Service operation. It spreads via fake Minecraft client and mod websites, YouTube links, Discord, and SEO poisoning. It steals session cookies, passwords, browser data, and cryptocurrency wallet contents, and used EtherHiding to retrieve active server addresses from the Ethereum blockchain to maintain infrastructure resilience.
WeedHack is a malware loader distributed through fake Minecraft client and mod download sites, poisoned search results, and links on trusted platforms such as Discord, MediaFire, GitHub, and Dropbox. It is delivered as infected JAR or ZIP files masquerading as Minecraft clients, cheats, or mods.
A multi-stage malware family distributed via fake Minecraft client websites, SEO poisoning, YouTube, file-hosting links, and spoofed GitHub repositories. Its JAR payloads collect system information, add Microsoft Defender exclusions, and steal sensitive data from compromised hosts.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.