Over 116,000 Mincraft systems infected in WeedHack malware campaign
A large-scale malware campaign dubbed WeedHack is targeting Minecraft players and has infected more than 116,000 systems since January. [...]
AI Analysis
Technical Summary
WeedHack is a malware-as-a-service campaign targeting Minecraft users by distributing malicious Java Archive (JAR) files masquerading as mods, clients, and cheats. It has infected over 116,000 systems since early 2026, with daily infections averaging 2,000 to 3,000. The malware steals sensitive information such as Minecraft session IDs, browser data, cryptocurrency wallets, and credentials for multiple communication platforms. The service offers a free tier with infostealing capabilities and a paid tier that enables remote control features including keylogging and webcam access. Distribution methods include YouTube videos with download links and SEO poisoning of search results for popular Minecraft clients. The operation is notable for its scale, use of legitimate-looking websites to deceive users, and a Telegram channel with over 800 members. McAfee telemetry and analysis underpin these findings.
Potential Impact
The campaign compromises user systems by stealing a wide range of sensitive data including Minecraft session IDs, browser cookies, saved passwords, cryptocurrency wallet information, and credentials for Discord, Steam, and Telegram. The premium version of the malware enables attackers to remotely control infected systems, capturing keystrokes, webcam footage, and managing files, which significantly increases the potential for privacy invasion, harassment, and further exploitation. The large infection count and daily infection rate indicate a widespread impact on the Minecraft player community, especially in the US, Germany, India, and the UK.
Mitigation Recommendations
Users should only download Minecraft mods and clients from official project sources or the in-game Minecraft Marketplace to avoid malicious files. Verify download links carefully and avoid JAR files from untrusted or dubious websites. There is no vendor patch or fix since this is malware distributed through third-party files, so prevention relies on user vigilance and safe download practices. Security teams should educate users about the risks of downloading unofficial Minecraft-related software and monitor for signs of infection. Since this is a MaaS campaign, blocking known distribution URLs and monitoring for related indicators may help reduce exposure.
Affected Countries
United States, Germany, India, United Kingdom
Over 116,000 Mincraft systems infected in WeedHack malware campaign
Description
A large-scale malware campaign dubbed WeedHack is targeting Minecraft players and has infected more than 116,000 systems since January. [...]
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
WeedHack is a malware-as-a-service campaign targeting Minecraft users by distributing malicious Java Archive (JAR) files masquerading as mods, clients, and cheats. It has infected over 116,000 systems since early 2026, with daily infections averaging 2,000 to 3,000. The malware steals sensitive information such as Minecraft session IDs, browser data, cryptocurrency wallets, and credentials for multiple communication platforms. The service offers a free tier with infostealing capabilities and a paid tier that enables remote control features including keylogging and webcam access. Distribution methods include YouTube videos with download links and SEO poisoning of search results for popular Minecraft clients. The operation is notable for its scale, use of legitimate-looking websites to deceive users, and a Telegram channel with over 800 members. McAfee telemetry and analysis underpin these findings.
Potential Impact
The campaign compromises user systems by stealing a wide range of sensitive data including Minecraft session IDs, browser cookies, saved passwords, cryptocurrency wallet information, and credentials for Discord, Steam, and Telegram. The premium version of the malware enables attackers to remotely control infected systems, capturing keystrokes, webcam footage, and managing files, which significantly increases the potential for privacy invasion, harassment, and further exploitation. The large infection count and daily infection rate indicate a widespread impact on the Minecraft player community, especially in the US, Germany, India, and the UK.
Mitigation Recommendations
Users should only download Minecraft mods and clients from official project sources or the in-game Minecraft Marketplace to avoid malicious files. Verify download links carefully and avoid JAR files from untrusted or dubious websites. There is no vendor patch or fix since this is malware distributed through third-party files, so prevention relies on user vigilance and safe download practices. Security teams should educate users about the risks of downloading unofficial Minecraft-related software and monitor for signs of infection. Since this is a MaaS campaign, blocking known distribution URLs and monitoring for related indicators may help reduce exposure.
Affected Countries
Technical Details
- Article Source
- {"url":"https://www.bleepingcomputer.com/news/security/over-116-000-mincraft-systems-infected-in-weedhack-malware-campaign/","fetched":true,"fetchedAt":"2026-06-02T22:03:34.376Z","wordCount":832}
Threat ID: 6a1f5336e29bf47b500acf96
Added to database: 6/2/2026, 10:03:34 PM
Last enriched: 6/2/2026, 10:03:46 PM
Last updated: 6/3/2026, 5:02:26 AM
Views: 19
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.