A massive malware operation disguised as Minecraft mods and game clients has infected more than 116,000 computers worldwide, with researchers warning that the campaign is also being used to harass and intimidate young gamers.
Quick Summary – TLDR:
- WeedHack has infected more than 116,000 systems since January 2026.
- The malware spreads through fake Minecraft mods, clients, YouTube videos, and malicious websites.
- Premium subscribers can gain access to victims’ webcams, screens, files, and keystrokes.
- Researchers found evidence that some users are leveraging the malware for cyberbullying and harassment, not just financial theft.
What Happened?
Security researchers at McAfee Labs have uncovered a large scale Malware as a Service operation called WeedHack that specifically targets Minecraft players. The campaign disguises malware as popular Minecraft mods, cheats, and custom clients, tricking users into downloading infected files.
According to the researchers, the operation has recorded more than 116,464 victim infections since January 2026 and continues to add roughly 2,000 to 3,000 new infections every day.
🚨 Big red flags for gamers and downloaders this week.
— The Hacker News (@TheHackersNews) June 3, 2026
🔸 Weedhack malware is hitting Minecraft players via YouTube fake mods and clients, stealing accounts and enabling remote spying.
🔸 CountLoader has infected 86,000 systems through cracked software.
🔸 Pirated streaming… pic.twitter.com/0294dAkmJJ
A Malware Business Built Around Minecraft
Minecraft remains the world’s best selling video game, with more than 350 million copies sold globally. Its massive ecosystem of third party mods, launchers, and customization tools has created a lucrative opportunity for cybercriminals.
Researchers say WeedHack operates like a legitimate software business. It offers both free and premium subscription tiers, allowing virtually anyone with a Discord account and internet connection to access the platform.
While many malware services are sold through underground forums and can cost hundreds of dollars per month, WeedHack lowers the barrier to entry dramatically. Premium access starts at just $5 per month, while a lifetime subscription reportedly costs $24.99.
The campaign provides customers with an enterprise style dashboard where they can monitor infected devices, access stolen information, configure notifications, review tutorials, and manage attacks through a web browser.
How the Malware Spreads?
Researchers identified more than 3,820 unique malicious JAR files and over 240 URLs linked to the operation.
The campaign relies heavily on two distribution methods:
YouTube Videos
Attackers create convincing Minecraft tutorial videos, client reviews, and gameplay demonstrations. These videos often include download links in descriptions and comments that redirect viewers to malicious websites.
In one example cited by researchers, a video promoting a Minecraft mod accumulated more than 7,500 views before being flagged.
The campaign even provides guidance for customers on creating professional looking videos with voiceovers, overlays, and search optimized titles to attract more victims.
Search Engine Manipulation
WeedHack operators also use SEO poisoning techniques to push fake Minecraft download websites higher in search results.
These sites frequently imitate legitimate mod pages and may include references to Discord servers, GitHub repositories, and security warnings to appear trustworthy.
Researchers observed attacks targeting well known Minecraft tools including Meteor Client, Radium Client, Wurst Client, LiquidBounce, Impact Client, Future Client, Aristois, Inertia Client, Salhack, Phobos, and Gamesense.
What Attackers Can Steal?
The free version of WeedHack functions as a powerful information stealer capable of collecting:
- Minecraft session IDs
- Browser passwords and cookies
- Discord, Steam, and Telegram credentials
- Cryptocurrency wallet information
- System details and screenshots
- Files matching targeted keywords
Premium subscribers receive additional capabilities, including:
- Live webcam access
- Screen sharing and remote control
- Keylogging
- Command line access
- Remote file uploads and downloads
Researchers also found that the malware uses a technique known as EtherHiding, leveraging the Ethereum blockchain to retrieve command and control infrastructure, making disruption efforts more difficult.
Cyberbullying Emerges as a Major Concern
One of the most alarming discoveries was how the malware is being used beyond financial theft.
Researchers uncovered a Telegram community with more than 850 members where users discussed the malware and shared content obtained from victims. Many participants appeared to be teenagers or young adults.
Investigators observed instances where attackers allegedly recorded victims through their webcams without consent and shared the footage as trophies. Others reportedly used stolen information and remote access capabilities to threaten or intimidate fellow players.
The findings suggest WeedHack is not only a cybercrime operation but also a growing tool for online harassment among younger internet users.
Global Impact
The campaign’s highest infection rates were recorded in the United States, followed by Germany, India, the United Kingdom, Italy, Vietnam, Canada, Norway, Sweden, Finland, and Spain.
Researchers also identified multiple domains associated with the operation, along with evidence linking the threat actor to several similar malware campaigns in the past.
SQ Magazine Takeaway
What stands out to me is not just the scale of WeedHack but how accessible it has become. A malware platform that offers powerful spying and account theft tools for the price of a fast food meal changes the threat landscape significantly.
The fact that researchers found evidence of teenagers using these capabilities to harass other players makes this story even more troubling. Minecraft has always thrived because of its creative community, but this campaign shows how easily trust can be exploited when users download mods from unverified sources.