Hacking

Weedhack Malware Minecraft Scam Targets Gamers

Published  ·  4 min read

If you're a Minecraft player looking for cool new clients or mods, watch out. Cybersecurity researchers found that several websites are still pushing a malware called Weedhack. They pretend to offer legit Minecraft clients, but they're actually out to steal your data.

McAfee Labs said they blocked more than 6,300 attempts to access these malicious sites. The fake sites look convincing. They copy branding, feature lists, FAQs, and installation guides. Some even use links to actual repositories on GitHub to appear legitimate.

The site had been built using Lovable, an AI website generator. This proves how simple it is now to build fake websites that are quite convincing.

Are you a Minecraft player? Well, this has everything to do with you. Here is an explanation of what is going on.

Quick Summary

What

Details

Malware

Weedhack

Target

Gamers looking for Minecraft clients

Tactics

SEO poisoning, fake websites

Platforms

Discord, MediaFire, GitHub

Detected

6,300+ access attempts

First Found

June 2026

How the Scam Works

Fake Websites

Attackers build copycat sites that look exactly like real Minecraft client projects. Branding, features, and even FAQ's are all stolen by them. It is made to seem so real that most people would not question it at all.

SEO Poisoning

SEO tactics are used by the scammers in order to have their fake website rank above the real one. Therefore, when searching for a Minecraft client, the fake website ranks above the real one.

Multi-Stage Attack

Once you download the fake client, a chain of events starts. The malware drops JAR payloads that steal system info, disable Microsoft Defender, and grab sensitive data from your computer.

Fake Domains to Watch Out For

Here are some of the fake domains McAfee found:

Fake Domain

What It Copies

glazed-client[.]com

glazedclient[.]com

radium-client[.]com

radiumclient[.]com

seedcrackerx.github[.]io

seedcrackerx[.]com

cheatlib[.]xyz

Claims to be a "modern Minecraft mod library"

meteorclients[.]com

meteorclient[.]com

22qq-client[.]com

A mod for Crystal PvP servers

kryptonclientcrack.lovable[.]app

kryptonclient[.]org

nova-client[.]com

An open-source Minecraft client

xenoclient[.]lol

Xenon client

xenonclient[.]com

Xenon client

Where the Malware Is Shared

McAfee found that attackers use familiar platforms to spread the malware:

Platform

Percentage

Discord

49.6%

MediaFire

23.4%

GitHub

8.2%


They also use Reddit, Planet Minecart, and EndMods.

What the Malware Does

Once installed, Weedhack can:

  • Collect system information
  • Disable Microsoft Defender
  • Steal sensitive data from your computer

How to Stay Safe

1. Download Only from Authentic Sources

Go always to the developer's official site. Do not believe everything you see in search results.

2. Look at the URL

Fake websites usually contain tiny mistakes. Be careful!

3. Scan Files Before Opening

Run any downloaded file through your security software first.

4. Don’t Take Any Threats to Your Security Seriously

Any modification or cheat asking you to turn off your antivirus is a major warning sign.

5. Keep Everything Updated

Update your operating system and security software regularly.

The Bigger Picture

SEO poisoning isn't new. In June 2026, Check Point also identified yet another similar campaign where the attackers leveraged open-source impostors to deliver malware, including Remus Stealer and AnimateClipper.

Bottom Line

Weedhack is using fake clients to hack into the Minecraft gaming community. They have been using techniques in SEO to position themselves high on search results.

What You Need to Know:

Key Point

Detail

Malware

Weedhack

Target

Minecraft gamers

Tactic

SEO poisoning + fake websites

Distribution

Discord, MediaFire, GitHub

Detected

6,300+ access attempts

What Do You Have To Do:

  • Access from legitimate sources
  • Verify website addresses
  • Scan downloaded documents
  • Update anti-virus software

FAQ Section

What is Weedhack malware?

It's a malware family that pretends to be Minecraft clients.It steals information from the system and other sensitive data.

How is it done?

They make fake websites for Minecraft and manipulate their SEO ranking. The user downloads the malware.

Where is malware shared by attackers?

They are shared on Discord, MediaFire, GitHub, Reddit, Planet Minecart, and EndMods.

How can I protect myself?

Only download from official sources. Check URLs. Scan files. Keep security software updated.

Has such a thing ever happened before?

Yes, a case of SEO poisoning was revealed in June 2026 by Check Point.

Source: The Hacker News
Professional Services

Explore Our Cybersecurity Services

Our insights are backed by hands-on service delivery. If your business needs professional cybersecurity support, our UK-based specialists are ready to help.

© 2016 – 2026 Red Secure Tech Ltd. Registered in England and Wales — Company No: 15581067