SendTech Times
News
MARKET SIGNAL:

WeedHack Malware Turns Minecraft Mods Into a 116,000-System Infostealer Campaign

Article summary

WeedHack has infected more than 116,000 systems by targeting Minecraft players through malicious mods, clients, cheats and utilities. McAfee telemetry shows 116,464 affected systems, 2,000 to 3,000 infections a day, more than 240 distribution URLs and 3,820 malicious JAR files. The next signal is whether Minecraft mod communities can move users back toward official download sources before infostealer distribution expands further.

WeedHack Malware Turns Minecraft Mods Into a 116,000-System Infostealer Campaign
Image source: BleepingComputer

Minecraft Mods Become an Infostealer Distribution Channel

A malware campaign called WeedHack has infected more than 116,000 systems since January by targeting Minecraft players through malicious mods, clients, cheats and utilities.

The campaign uses YouTube promotion and search-engine poisoning to push downloads that look like game tools.

McAfee telemetry shows 116,464 affected systems, with 2,000 to 3,000 infections a day.

The largest victim concentrations identified in the report are in the United States, Germany, India and the UK.

The campaign's scale is visible in more than 240 distribution URLs and 3,820 unique malicious JAR files.

For consumer-security teams, the practical risk is that a gaming mod can become a credential-theft path before users recognize it as a security problem.

Free Malware Tools Lower The Abuse Barrier

WeedHack operates as a malware-as-a-service infostealer with a dashboard that lets users view stolen credentials and data from compromised systems.

McAfee described the use of ordinary public web hosting, rather than hidden dark-web distribution, and the free access model as unusual for an infostealer operation.

The free tier targets Minecraft session IDs, cookies and saved passwords across 36 browsers, 56 cryptocurrency add-ons and 12 desktop cryptocurrency wallet apps.

It also targets Discord, Steam and Telegram credentials and can capture screenshots.

A premium tier costs $5 per month and also offers a lifetime purchase option.

That version adds remote control with mouse and keyboard input, webcam access, a keylogger, remote shell access and remote file management.

The paid feature set changes the consumer-risk profile because a campaign that begins with a fake game utility can extend into direct control over the compromised device.

Social Proof Is Part Of The Attack Surface

McAfee researchers said the campaign reaches victims mainly through YouTube videos and poisoned search results.

Some videos include voice-over narration to appear more authentic and have drawn more than 7,500 views.

The attack also copies legitimacy signals from real projects.

In one example, a malicious site warned users to download Skytils only from the official site while linking to the legitimate GitHub repository and Discord server, creating a false sense of safety around the fake page.

For players, the safer control is source discipline: avoid mod links promoted through videos or search results, and verify downloads through the project's official site or repository rather than a lookalike landing page.

The next signal is whether Minecraft players and mod communities shift downloads back toward official project sources before WeedHack-style distribution keeps scaling through video promotion and search traffic.

Share this article
inXf

Related articles

More
CISA WebLogic Warning Turns Oracle Patch Lag Into an Exposure Test
Cybersecurity

CISA WebLogic Warning Turns Oracle Patch Lag Into an Exposure Test

CISA ordered U.S. federal agencies to patch Oracle WebLogic Server systems affected by CVE-2024-21182 after active exploitation was observed. Shodan tracks more than 1,592 exposed WebLogic servers vulnerable to the flaw, including 961 on version 12.2.1.4.0 and 631 on version 14.1.1.0.0. The immediate test is whether public- and private-sector defenders apply Oracle fixes or remove exposed systems where mitigations are unavailable.

AI-Built Ransomware Toolkit Turns EDR Evasion Into a Faster Cybercrime Workflow
Cybersecurity

AI-Built Ransomware Toolkit Turns EDR Evasion Into a Faster Cybercrime Workflow

A ransomware-focused threat actor adopted an AI-built toolkit for Active Directory discovery and endpoint detection and response evasion. Sophos found Cursor and Claude Opus agents assisted development, with close to 80 modules tested against more than 70 techniques. The practical test is whether defenders can shorten validation cycles as AI accelerates the move from offensive research to working malware components.

Palo Alto Sell-Off Shows AI Cybersecurity Demand Still Has a Timing Problem
Cybersecurity

Palo Alto Sell-Off Shows AI Cybersecurity Demand Still Has a Timing Problem

Palo Alto Networks shares fell more than 4% after stronger quarterly results and current-quarter guidance failed to satisfy investors looking for faster AI-linked earnings upside. CEO Nikesh Arora reiterated a fiscal 2030 target of more than 4,000 platformizations and a USD 20 billion NGS ARR goal. The practical test is whether AI-related security demand turns into NGS ARR progress as data center infrastructure is ordered, installed and brought online.

NFSP Ransomware Attack Turns Supplier Email Pause Into a Security-Control Test
Cybersecurity

NFSP Ransomware Attack Turns Supplier Email Pause Into a Security-Control Test

The National Federation of Subpostmasters was hit by ransomware after a cPanel-related hosting software bug was exploited. The NFSP was targeted on 30 April, and the Post Office paused some email interactions with the federation while saying branch operations were not affected. The immediate test is whether trusted communications can resume without pushing subpostmasters toward insecure workaround channels.

Keep Reading

More Stories

Latest
AT&T Satellite Strategy Turns Direct-To-Device Into A Rural Coverage TestScience & TechJun 10, 2026AT&T Satellite Strategy Turns Direct-To-Device Into A Rural Coverage TestAT&T is framing direct-to-device satellite connectivity as a rural coverage complement, not a threat to terrestrial networks, while cooperating with Verizon and T-Mobile despite different satellite partners.Meta-Reliance Jamnagar Deal Tests India’s AI Data Center AmbitionCloud & Data CentersJun 10, 2026Meta-Reliance Jamnagar Deal Tests India’s AI Data Center AmbitionMeta and Reliance will collaborate on a 168-megawatt AI-enabled data center in Jamnagar, moving their partnership from digital services into infrastructure and testing India as a global AI compute hub.Taiwan AI Chip Control Plan Tests Asia's Semiconductor Enforcement GapScience & TechJun 10, 2026Taiwan AI Chip Control Plan Tests Asia's Semiconductor Enforcement GapTaiwan is weighing stricter AI chip export controls that could criminalize smuggling of Nvidia-class hardware to China, raising compliance pressure on server assemblers and deepening Asia's split over US-aligned semiconductor enforcement.Amazon Leo FCC Extension Keeps Starlink Satellite Rivalry AliveScience & TechJun 10, 2026Amazon Leo FCC Extension Keeps Starlink Satellite Rivalry AliveThe FCC gave Amazon Leo a 24-month extension for its interim LEO satellite deployment milestone, preserving a path toward a mid-2026 service launch while keeping the July 30, 2029 full-buildout deadline in place.Gulf Hiring Freezes Put AI And Digital Transformation Skills At RiskEconomyJun 10, 2026Gulf Hiring Freezes Put AI And Digital Transformation Skills At RiskGulf companies are using hiring freezes to protect costs, but source-backed labour data shows continued shortages in AI, technology, fintech, compliance and digital transformation roles. The risk is that broad freezes can weaken delivery and retention just as skilled workers in the UAE and Saudi Arabia see strong job-market alternatives.Blue Owl ADGM Office Turns Abu Dhabi Finance Growth Into A Private-Credit SignalEconomyJun 10, 2026Blue Owl ADGM Office Turns Abu Dhabi Finance Growth Into A Private-Credit SignalBlue Owl Capital is opening a regional headquarters in ADGM, adding a $315 billion asset manager to Abu Dhabi financial hub as the centre reports 57% first-quarter growth in assets under management.Belfast Knife Attack Turns Into Public-Order And Migration Test For UK AuthoritiesPoliticsJun 10, 2026Belfast Knife Attack Turns Into Public-Order And Migration Test For UK AuthoritiesPolice in Northern Ireland are investigating a serious Belfast knife attack as attempted murder while urging calm after residents intervened and online footage triggered public-order concerns.Sandstone Raises $30M For AI Workflow Tools In Company Legal TeamsScience & TechJun 10, 2026Sandstone Raises $30M For AI Workflow Tools In Company Legal TeamsSandstone raised $30 million in Series A funding led by Lightspeed Venture Partners to build AI workflow tools for in-house legal teams at small and mid-sized businesses.SpaceX Fixed-Price IPO Turns Retail Allocation Into The Main Market TestScience & TechJun 10, 2026SpaceX Fixed-Price IPO Turns Retail Allocation Into The Main Market TestSpaceX is offering IPO shares at a fixed $135 price, leaving allocation of roughly $75 billion in shares, especially retail access, as the main test before Thursday offering and Friday trading.UAE Salary Deadline Turns WPS Payroll Into A First-Of-Month Payments TestFintech & Digital PaymentsJun 10, 2026UAE Salary Deadline Turns WPS Payroll Into A First-Of-Month Payments TestUAE private-sector salary rules triggered a sharp WPS payroll surge on June 1, with Al Ansari Exchange up more than 151 per cent and Al Fardan Exchange up 136 per cent, turning wage compliance into a first-of-month payments and cash-flow test.Sabertooth's $500 Million SPV Push Turns AI Startup Access Into A ProductAIJun 10, 2026Sabertooth's $500 Million SPV Push Turns AI Startup Access Into A ProductSabertooth Capital has invested nearly $500 million into 10 late-stage AI and deep-tech companies through single-deal SPVs, showing how access to scarce private technology rounds is becoming a product of its own.Google's $4.99 AI Plus Cut Turns Consumer AI Into A Bundle FightAIJun 10, 2026Google's $4.99 AI Plus Cut Turns Consumer AI Into A Bundle FightGoogle cut AI Plus from $7.99 to $4.99 per month and doubled included storage to 400 gigabytes, pushing U.S. consumer AI subscriptions toward lower-priced platform bundles.