< Back to all clusters
[TECHNOLOGY] · 5 sources

started · updated

Weedhack malware targets gamers via fake Minecraft clients

Cybersecurity researchers at McAfee Labs have identified an ongoing campaign involving the Weedhack malware family, which targets gamers by masquerading as legitimate Minecraft clients. The attackers utilize SEO poisoning and YouTube to redirect users to fraudulent websites that mimic official projects, complete with fake branding, FAQs, and installation guides.

McAfee Labs reported blocking more than 6,300 attempts to access these malicious sites. The infection process involves multi-stage JAR payloads designed to steal sensitive data, collect system information, and create exclusions in Microsoft Defender.

Attackers are leveraging familiar platforms to distribute the malware, with Discord links accounting for 49.6% of identified malicious URLs, followed by MediaFire (23.4%) and GitHub (8.2%). Notably, one malicious site was built using Lovable, an AI-powered website builder, demonstrating how accessible AI tools can be used to create convincing fraudulent domains.

Entities

Discord · GitHub · McAfee Labs · MediaFire · Minecraft

Claims

What the coverage asserts, and how many sources carry each claim.

  • [● 2 SOURCES] One of the malicious websites was constructed using the AI-powered website builder Lovable.
  • [● 2 SOURCES] Approximately 49.6% of identified malicious URLs were Discord links, 23.4% were MediaFire, and 8.2% were GitHub.
  • [● 2 SOURCES] Attackers use SEO poisoning and YouTube to redirect users to fraudulent domains.
  • [● 2 SOURCES] McAfee Labs detected and blocked over 6,300 attempts to access malicious sites.
  • [● 3 SOURCES] The Weedhack malware uses multi-stage JAR payloads to collect system information, steal sensitive data, and set up Microsoft Defender exclusions. www.it-boltwise.de