惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园_首页
IT之家
IT之家
博客园 - Franky
Stack Overflow Blog
Stack Overflow Blog
宝玉的分享
宝玉的分享
Recent Announcements
Recent Announcements
Engineering at Meta
Engineering at Meta
S
SegmentFault 最新的问题
V
Visual Studio Blog
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Last Week in AI
Last Week in AI
H
Help Net Security
V
V2EX
H
Hackread – Cybersecurity News, Data Breaches, AI and More
量子位
博客园 - 叶小钗
J
Java Code Geeks
博客园 - 【当耐特】
月光博客
月光博客
爱范儿
爱范儿
人人都是产品经理
人人都是产品经理
酷 壳 – CoolShell
酷 壳 – CoolShell
小众软件
小众软件

Help Net Security

Police arrest 10 suspected members of Black Axe cybercrime gang ShinyHunters claims it stole 1.4 million records from Udemy Sevii unveils Cyber Swarm Defense Mode to stop AI-driven attacks at scale Alleged Chinese hacker extradited to US over cyberattacks targeting COVID-19 research Cequence Agent Personas bring granular control and governance to enterprise AI agents NowSecure MARI gives enterprises evidence-based visibility into third-party mobile app risk The metrics killing your SOC, and what to use instead US state privacy fines reached $3.425 billion in 2025 Canada’s first SMS blaster case leads to three arrests Linux storage management tool Stratis 3.9.0 adds online encryption and cache-less pool startup TLS Connect gives SMBs a right-sized automated tool to manage TLS certificates Aptori expands its platform with autonomous offensive testing to reduce security bottlenecks Your IAM was built for humans, AI agents don’t care The AI criminal mastermind is already hiring on gig platforms 25 open-source cybersecurity tools that don’t care about your budget Product showcase: LuLu reveals unauthorized outbound connections from Mac apps Week in review: Claude Mythos finds 271 Firefox flaws, Vercel breach Users advised to drop passwords and make room for passkeys - Help Net Security Indirect prompt injection is taking hold in the wild - Help Net Security Compromised everyday devices power Chinese cyber espionage operations - Help Net Security New Cisco firewall malware can only be killed by pulling the plug - Help Net Security Meta is overhauling how you sign in, manage settings, and protect your accounts - Help Net Security Ubuntu 26.04 LTS delivers memory-safe system tools and live patching for Arm servers - Help Net Security OpenAI’s GPT-5.5 is out with expanded cybersecurity safeguards - Help Net Security AI is speeding up nation-state cyber programs - Help Net Security A study of 1,000 Android apps finds a privacy policy logging gap - Help Net Security IT spending to hit $6.31 trillion record, thanks to AI - Help Net Security Where AI in CI/CD is working for engineering teams - Help Net Security With AI's help, North Korean hackers stumbled into a near-undetectable attack - Help Net Security Hacker with a special interest in breaching sports institutions ends behind bars - Help Net Security
Malware campaign targeting Minecraft users infects over 1...
Sinisa Markovic · 2026-06-03 · via Help Net Security

A Malware-as-a-Service (MaaS) operation named WeedHack is targeting Minecraft users and allows threat actors to gain remote access to victims’ screens, webcams, and files through a web-based dashboard, McAfee researchers found.

Minecraft, developed by Mojang Studios and released in 2011, is one of the best-selling video games of all time, with more than 350 million copies sold worldwide.

Since January 2026, the campaign has infected more than 116,000 systems and continues to add between 2,000 and 3,000 new infections per day.

“We’ve discovered over 3,820 unique malicious JAR files that are part of this attack and over 240 URLs responsible for distributing this malware,” researchers said.

The United States accounted for the largest share of WeedHack infections, followed by Germany, India, the United Kingdom, Italy, Vietnam, Canada, Norway, Sweden, Finland, and Spain.

YouTube spreading and SEO poisoning

The WeedHack campaign relies on YouTube-driven distribution and SEO poisoning to reach victims.

On YouTube, attackers promote Minecraft mods, clients, and utilities through videos containing download links in descriptions and comments. Some well-made videos feature voice-over narration and have attracted more than 7,500 views.

Minecraft malware campaign

YouTube video promoting malicious Minecraft Mods (Source: McAfee)

“WeedHack targets Minecraft clients and mods without an official website that are hosted exclusively on file hosting websites like GitHub and specifically select mods with unique names, so it is easier to dominate search engine results,” McAfee explained.

Lowering the barrier to entry

What sets WeedHack apart from other malware campaigns is how accessible it is. The platform is hosted on the clear web and provides access to sophisticated malware for free.

Researchers noted that MaaS offerings such as Lumma Stealer and X-Worm typically cost hundreds of dollars per month or require lifetime subscriptions purchased through underground forums, dark web marketplaces, or Telegram channels. WeedHack offers the malware for free, with premium features starting at $5 per month and lifetime access available for $24.99.

The free tier includes an infostealer that targets Minecraft session IDs and four Minecraft launchers, collects system information, and steals cookies and passwords from 36 browsers.

It also targets 56 browser-based cryptocurrency wallets and 12 desktop cryptocurrency wallets, along with Discord, Steam, and Telegram credentials. The malware can search infected systems using 24 predefined keywords and capture screenshots from compromised devices.

Premium subscriptions unlock remote-access capabilities including webcam access, keystroke logging, reverse shell execution, screen sharing with keyboard and mouse control, and tools for uploading and downloading files.

Tools, tutorials, and infection tracking

At the center of the operation is a web-based dashboard that gives customers access to data collected from compromised systems. Victim profiles contain screenshots, system information, IP addresses, usernames, computer names, and harvested credentials, while a separate section tracks Minecraft session hits used for account hijacking.

The platform includes a payload builder capable of injecting malware into legitimate Minecraft mods targeting versions 1.21.0 through 1.21.11. Users can also view all-time and 24-hour infection statistics through a leaderboard refreshed every 10 minutes.

Documentation available through the portal covers malware distribution, operational security practices, remote-access features, stolen credentials, VPN and proxy services, and troubleshooting.

A suggestions page allows users to submit feature requests and vote on proposed additions, including ransomware functionality, microphone access, and support for additional Minecraft clients.

Beyond account theft and credential harvesting, the platform appears to have fueled cyberbullying. The operation’s Telegram channel attracted more than 850 members, with activity indicating that teenagers and young adults were using WeedHack’s remote-access tools to monitor, threaten, and harass victims.

McAfee advises users to be cautious of recently uploaded YouTube videos promoting Minecraft tools, downloads hosted outside official websites, and requests to disable antivirus software before installation.