WeedHack Malware Persists as Fake Minecraft Sites Survive C2 Disruption
The FBI and partners took down WeedHack, a service that sold malware to steal Minecraft accounts and control users' devices. The people behind it were arrested.
- Report priority
- Medium
How it works
- WeedHack sold malware to attackers who used fake Minecraft sites and search tricks to trick users into downloading infected files.
- These files stole account passwords and let attackers control users' computers.
- The service also had a dashboard where attackers could track infected devices.
What to do
If you downloaded Minecraft files from untrusted sites or clicked on suspicious search results, check your device for unusual activity or unauthorized logins in your Minecraft account.
If you suspect your device or account was compromised, change your Minecraft password immediately and scan your device with trusted antivirus software. Monitor your account for any unauthorized changes. If you used WeedHack-related services, contact Minecraft support for further guidance.
Technical details
WeedHack is a malware-as-a-service (MaaS) operation that distributes credential-stealing and remote-access malware through fake Minecraft mods, clients, and other downloads. Attackers use SEO poisoning and cloned project pages to trick users into downloading malicious JAR files from seemingly legitimate sources. The campaign leverages trusted platforms like Discord (49.6% of malicious URLs), MediaFire (23.4%), GitHub (8.2%), and Dropbox (4.6%) to host the malware, often mimicking genuine branding, installation guides, and GitHub repositories.
WeedHack can steal Minecraft session IDs, browser passwords and cookies, messaging/gaming credentials, cryptocurrency wallet data, screenshots, and system information. A premium tier, priced at $5/month, adds webcam access, keylogging, reverse-shell execution, screen control, and file management. Disrupting its command-and-control (C2) infrastructure did not halt distribution, with over 6,300 attempts to reach malicious sites observed in a one-month period.
The campaign was first documented in June 2023 with 3,820 malicious JAR files across 240 URLs.