Weedhack Malware Distributed Through Fake Minecraft Client Sites in Ongoing SEO Poisoning Campaign
What Happened
McAfee Labs researchers report that a malware family tracked as Weedhack is being actively distributed through websites impersonating legitimate Minecraft client projects. According to the report, McAfee detected and blocked more than 6,300 attempts to access the malicious sites. The lookalike sites reproduce branding, feature lists, and FAQs from genuine gaming projects, and appear to rely on SEO poisoning to surface in search results when gamers look for Minecraft mods or clients.
Why It Matters
Gaming-lure campaigns like this one target a broad, largely non-enterprise population, but the same infrastructure and delivery techniques (search-result manipulation, brand impersonation, trojanized installers) are commonly reused against corporate and BYOD endpoints. Organizations that allow personal software installs on managed or dual-use devices, or that permit gaming-related traffic, may see this malware land on endpoints with access to corporate resources. The specific capabilities and objectives of Weedhack itself are not detailed in the available reporting.
What Defenders Should Watch For
- Downloads of Minecraft client/launcher executables from domains that are not the official Minecraft/Mojang/Microsoft properties or well-known modding platforms (e.g., Modrinth, CurseForge).
- Search and browsing telemetry showing users landing on gaming sites via unusual or newly registered domains, especially where the site closely mirrors an established project's branding.
- Endpoint execution of installers or archives sourced from browser downloads folders shortly after visiting gaming-related sites, followed by unexpected outbound connections.
- Web/DNS filtering and reputation feeds for newly observed domains impersonating popular gaming software, and blocking known-bad Weedhack distribution sites if indicators become available.
- User awareness reminders to download game clients and mods only from official sources or well-known repositories, particularly on any device with access to corporate resources.
Developing Intel
This is a net-new, ongoing campaign with details still emerging; McAfee's write-up does not include full technical indicators or a deep malware analysis in the summary available here. This post will be revisited as more indicators and analysis become public. Read the original report at The Hacker News.