Weedhack Malware Continues to Target Gamers Via Fake Minecraft Clients and SEO Poisoning
Cybersecurity researchers have uncovered ongoing campaigns distributing the **Weedhack** malware family. Threat actors are leveraging fake **Minecraft** client websites and sophisticated SEO poisoning techniques to trick gamers into downloading malicious files, highlighting a persistent threat in the gaming community.
Cybersecurity researchers have issued a fresh warning regarding the persistent **Weedhack** malware family. Attackers are actively distributing this malware by masquerading as legitimate **Minecraft** clients, primarily targeting the gaming community.
**McAfee Labs** reports detecting and blocking over 6,300 attempts to access these malicious sites. The researchers found numerous lookalike gaming websites meticulously crafted to mimic genuine **Minecraft** projects. These deceptive sites often feature authentic-looking branding, feature lists, FAQs, installation guides, developer credits, and even links to legitimate **GitHub** repositories, making them highly convincing.

### AI Tools Lower Barrier to Entry
Notably, one of the identified malicious sites was built using **Lovable**, an artificial intelligence (AI)-powered website builder. This demonstrates how readily available AI tools can significantly lower the barrier for threat actors, enabling them to launch new, highly convincing malicious sites with greater ease.
**Weedhack** was initially documented by **McAfee Labs** in June 2026. At that time, the cybersecurity firm detailed its use of SEO poisoning and **YouTube** to redirect traffic to bogus domains. The attack sequence is multi-stage, culminating in the deployment of **JAR** payloads. These payloads are designed to collect system information, establish **Microsoft Defender** exclusions, and steal sensitive data from compromised hosts.
### Multi-Platform Distribution
"Nearly half of the malicious URLs identified were **Discord** links (49.6%), followed by **MediaFire** (23.4%) and **GitHub** (8.2%), showing how attackers can use familiar platforms alongside fake websites to distribute malware," stated **McAfee Labs** researcher **Aayush Tyagi**.
Some of the fake domains distributing the malware include:
* `glazed-client[.]com` (replicating `glazedclient[.]com`)
* `radium-client[.]com` (replicating `radiumclient[.]com`)
* `seedcrackerx.github[.]io` (replicating `seedcrackerx[.]com`)
* `cheatlib[.]xyz`
* `meteorclients[.]com` (replicating `meteorclient[.]com`)
* `22qq-client[.]com`
* `kryptonclientcrack.lovable[.]app` (replicating `kryptonclient[.]org`)
* `nova-client[.]com`
* `xenoclient[.]lol` and `xenonclient[.]com` (impersonating **Xenon client**)
Crucially, several of these spoofed websites, such as those for **Xenon Client** and **Nova Client**, have achieved top rankings in search results across major engines like **Google**, **Microsoft Bing**, **Brave Search**, and **DuckDuckGo**. This allows unsuspecting users to easily encounter and download **Weedhack**-laced clients.
"The legitimate client is hosted on **GitHub** and **Modrinth**; however, attackers have created a spoofed website and leveraged SEO poisoning techniques to outrank the official sources in search results," **McAfee Labs** explained.
Beyond bogus domains, **Weedhack** is also being spread through file hosting services and **GitHub** repositories. Links to these malicious sources are then distributed via platforms like **Discord**, **Reddit**, and other communication channels. Another concerning propagation method involves hosting the malicious **JAR** files on legitimate **Minecraft** resource sites like **Planet Minecart** and **EndMods**.
### Mitigating the Threat
To protect against such threats, users and IT security professionals are advised to:
* Keep all devices and software up-to-date.
* Strictly adhere to trusted and official sources for software downloads.
* Scan all downloaded files with reputable antivirus software before opening them.
* Exercise extreme caution if any mod or client prompts to disable security protections prior to installation.
This isn't an isolated incident. In June 2026, **Check Point** highlighted a large-scale operation using similar SEO poisoning tactics. That campaign impersonated open-source and freeware projects to funnel users through a **Traffic Distribution System (TDS)**, ultimately delivering malware families such as **Remus Stealer**, **AnimateClipper**, and the **SessionGate** framework.