惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

I
InfoQ
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Apple Machine Learning Research
Apple Machine Learning Research
月光博客
月光博客
B
Blog
罗磊的独立博客
GbyAI
GbyAI
博客园 - 三生石上(FineUI控件)
雷峰网
雷峰网
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Microsoft Security Blog
Microsoft Security Blog
宝玉的分享
宝玉的分享
The GitHub Blog
The GitHub Blog
人人都是产品经理
人人都是产品经理
博客园 - Franky
有赞技术团队
有赞技术团队
WordPress大学
WordPress大学
博客园 - 聂微东
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
V
Visual Studio Blog
MyScale Blog
MyScale Blog
Google DeepMind News
Google DeepMind News
G
Google Developers Blog
aimingoo的专栏
aimingoo的专栏

Help Net Security

ChatGPT advanced account security adds passkeys and hardware keys Week in review: High-severity LPE vulnerability in the Linux kernel, cPanel 0-day exploited for months Automating Pentest Delivery: A Step-by-Step Guide - PlexTrac Open-source privacy proxy masks PII before prompts reach external AI services Shadow AI risks deepen as 31% of users get no employer training Identity is the control plane for distributed infrastructure AI traffic is getting bigger, louder, and less predictable New infosec products of the month: April 2026 cPanel zero-day exploited for months before patch release (CVE-2026-41940) Cisco releases open-source toolkit for verifying AI model lineage Met Police face criticism for using AI to spy on their own officers Nine-year-old Linux kernel flaw enables reliable local privilege escalation (CVE-2026-31431) Hacker with a special interest in breaching sports institutions ends behind bars - Help Net Security IP Fabric MCP server adds governance and control to enterprise AIOps workflows - Help Net Security Aqua Compass MCP server enables real-time investigation and containment of runtime threats - Help Net Security Google brings instant email verification to Android, no OTP needed - Help Net Security If cyber espionage via HDMI worries you, NCSC built a device to stop it - Help Net Security Apple fixes iPhone bug that let FBI retrieve deleted Signal messages(CVE-2026-28950) - Help Net Security GopherWhisper APT group hides command and control traffic in Slack and Discord - Help Net Security OpenAI tackles a bad habit people have when interacting with AI - Help Net Security A year in, Zoom's CISO reflects on balancing security and business - Help Net Security Scenario: Open-source framework for automated AI app red-teaming - Help Net Security GDPR works, but only where someone enforces it - Help Net Security Ransomware, fraud, and lawsuits drive cyber insurance claims to new peaks - Help Net Security Google’s Workspace Intelligence promises privacy while running on your data - Help Net Security Cyberattack on French government agency triggers phishing alert - Help Net Security Claude Mythos finds 271 Firefox flaws, Mozilla believes zero-days are numbered - Help Net Security Prove Identity Platform connects verification, authentication, and fraud prevention - Help Net Security New Mirai variants target routers and DVRs in parallel campaigns - Help Net Security Acronis GenAI Protection gives MSPs control over AI usage and data risks - Help Net Security
Malware campaign targeting Minecraft users infects over 1...
Sinisa Markovic · 2026-06-03 · via Help Net Security

A Malware-as-a-Service (MaaS) operation named WeedHack is targeting Minecraft users and allows threat actors to gain remote access to victims’ screens, webcams, and files through a web-based dashboard, McAfee researchers found.

Minecraft, developed by Mojang Studios and released in 2011, is one of the best-selling video games of all time, with more than 350 million copies sold worldwide.

Since January 2026, the campaign has infected more than 116,000 systems and continues to add between 2,000 and 3,000 new infections per day.

“We’ve discovered over 3,820 unique malicious JAR files that are part of this attack and over 240 URLs responsible for distributing this malware,” researchers said.

The United States accounted for the largest share of WeedHack infections, followed by Germany, India, the United Kingdom, Italy, Vietnam, Canada, Norway, Sweden, Finland, and Spain.

YouTube spreading and SEO poisoning

The WeedHack campaign relies on YouTube-driven distribution and SEO poisoning to reach victims.

On YouTube, attackers promote Minecraft mods, clients, and utilities through videos containing download links in descriptions and comments. Some well-made videos feature voice-over narration and have attracted more than 7,500 views.

Minecraft malware campaign

YouTube video promoting malicious Minecraft Mods (Source: McAfee)

“WeedHack targets Minecraft clients and mods without an official website that are hosted exclusively on file hosting websites like GitHub and specifically select mods with unique names, so it is easier to dominate search engine results,” McAfee explained.

Lowering the barrier to entry

What sets WeedHack apart from other malware campaigns is how accessible it is. The platform is hosted on the clear web and provides access to sophisticated malware for free.

Researchers noted that MaaS offerings such as Lumma Stealer and X-Worm typically cost hundreds of dollars per month or require lifetime subscriptions purchased through underground forums, dark web marketplaces, or Telegram channels. WeedHack offers the malware for free, with premium features starting at $5 per month and lifetime access available for $24.99.

The free tier includes an infostealer that targets Minecraft session IDs and four Minecraft launchers, collects system information, and steals cookies and passwords from 36 browsers.

It also targets 56 browser-based cryptocurrency wallets and 12 desktop cryptocurrency wallets, along with Discord, Steam, and Telegram credentials. The malware can search infected systems using 24 predefined keywords and capture screenshots from compromised devices.

Premium subscriptions unlock remote-access capabilities including webcam access, keystroke logging, reverse shell execution, screen sharing with keyboard and mouse control, and tools for uploading and downloading files.

Tools, tutorials, and infection tracking

At the center of the operation is a web-based dashboard that gives customers access to data collected from compromised systems. Victim profiles contain screenshots, system information, IP addresses, usernames, computer names, and harvested credentials, while a separate section tracks Minecraft session hits used for account hijacking.

The platform includes a payload builder capable of injecting malware into legitimate Minecraft mods targeting versions 1.21.0 through 1.21.11. Users can also view all-time and 24-hour infection statistics through a leaderboard refreshed every 10 minutes.

Documentation available through the portal covers malware distribution, operational security practices, remote-access features, stolen credentials, VPN and proxy services, and troubleshooting.

A suggestions page allows users to submit feature requests and vote on proposed additions, including ransomware functionality, microphone access, and support for additional Minecraft clients.

Beyond account theft and credential harvesting, the platform appears to have fueled cyberbullying. The operation’s Telegram channel attracted more than 850 members, with activity indicating that teenagers and young adults were using WeedHack’s remote-access tools to monitor, threaten, and harass victims.

McAfee advises users to be cautious of recently uploaded YouTube videos promoting Minecraft tools, downloads hosted outside official websites, and requests to disable antivirus software before installation.